## Overview
CISA added CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) list on September 27, 2026. This vulnerability affects Citrix NetScaler ADC and NetScaler Gateway. It allows for remote code execution or denial of service. The inclusion in the KEV list indicates a federal deadline for mitigation.
## Technical Details
The vulnerability arises from improper restriction of operations within the bounds of a memory buffer. Affected versions include NetScaler ADC before 14.1-73.37 and 13.1-64.23, as well as NetScaler Gateway before 14.1-73.37 and 13.1-64.23. The issue also impacts specific FIPS and NDcPP versions. Attackers can exploit this flaw to execute arbitrary code or crash the service.
## Impact
Successful exploitation of CVE-2026-88772 can lead to severe consequences, including unauthorized access to sensitive data or service interruptions. Organizations using vulnerable versions of Citrix NetScaler products are at risk of significant operational disruptions.
## Mitigation
Defenders should immediately update their Citrix NetScaler ADC and Gateway to the latest versions. Specifically, upgrade to 14.1-73.37 or 13.1-64.23 or later. Regularly monitor for advisories from Citrix and apply patches as they become available. Additionally, consider implementing network segmentation and access controls to limit exposure.
CSURFACE Threat Sensor