CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
CVE-2026-88772 is a memory buffer bounds vulnerability in Citrix NetScaler ADC and NetScaler Gateway. Improper restriction of operations within a memory buffer can lead to remote code execution or denial of service, which matters because these products often sit at the network edge and handle authentication and application delivery for many organizations.
Public detail beyond the CISA summary is limited here. Confirm exact affected builds, fixed releases, and any configuration prerequisites against the vendor advisory before you act.
How it works
This issue is classified as CWE-119: improper restriction of operations within the bounds of a memory buffer. In products of this class, code that reads or writes memory does not correctly enforce size or boundary checks. An attacker who can reach the vulnerable processing path may supply input that causes the process to operate outside the intended buffer.
At a high level, successful abuse of such a flaw can corrupt memory in ways that crash the service (denial of service) or, in worse cases, allow execution of attacker-controlled code in the context of the affected process. The CISA summary states that remote code execution or denial of service is possible. Do not invent or assume specific packets, endpoints, or exploit steps; those details, if any, must come from the vendor advisory and your own controlled analysis.
Am I affected? How to find it in your systems
Citrix NetScaler ADC and NetScaler Gateway typically run as appliances or virtual appliances in DMZs, as reverse proxies, load balancers, SSL VPN / remote-access gateways, and application delivery controllers. Inventory every instance that terminates client or partner traffic, including HA pairs, clouds, and lab systems that may still be reachable.
- Build an asset list from CMDB, network discovery, certificate inventories, and management consoles; record build/version strings exactly as the appliance reports them.
- Compare those versions and any cited configurations only to the vendor advisory for CVE-2026-88772; this record does not list version numbers.
- Note internet-facing versus internal-only exposure; edge placement raises priority under risk-based patching guidance such as CISA BOD 26-04.
- For exploitation signs, watch process crashes, unexpected restarts of NetScaler-related services, anomalous management or data-plane traffic, new or unexpected admin sessions, and integrity failures on system binaries or configs. Correlate with external IDS/IPS and firewall logs. Specific IoCs are not provided in the facts above—confirm any published indicators with the vendor and your threat intel sources.
How to remediate
Patch first. Apply the vendor update or mitigation package named in the official Citrix advisory for CVE-2026-88772. Follow CISA’s required action: apply mitigations in accordance with vendor instructions, ensure compliance with BOD 26-04 prioritization based on risk, and follow CISA’s forensics triage requirements where applicable. For cloud-hosted or managed instances, follow applicable BOD 26-04 cloud guidance. If mitigations are unavailable, discontinue use of the product as directed by that guidance.
- Schedule maintenance windows for HA pairs so one node is upgraded and validated before failover.
- After upgrade, verify version strings, core services, certificates, and critical virtual servers or gateway features.
- Hardening for this class: reduce unnecessary features and listeners, enforce least privilege on management access, keep management interfaces off the public internet, and maintain current firmware hygiene across the estate.
If you can't patch immediately
Use compensating controls only as a bridge until the vendor fix is applied.
- Segmentation: restrict which networks can reach the appliance’s management and vulnerable data-plane interfaces; prefer allowlists over broad exposure.
- Virtual patching / WAF: if you have a capable reverse proxy or WAF in front, apply vendor- or community-informed rules for this product class only after validating they do not break legitimate traffic; treat this as temporary.
- Disable or restrict nonessential gateway or ADC features that expand attack surface, if your operations allow it and the advisory supports that path.
- Monitoring: heighten alerting on crashes, config changes, authentication anomalies, and outbound connections from the appliance; retain logs for forensic triage consistent with CISA guidance.
- Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26-04 patching timelines; prolonged delay increases risk of RCE or service outage.
If your data may have been exposed
Actively exploited edge vulnerabilities can lead to full compromise of the appliance and downstream access to applications or credentials. Known ransomware use is not documented for this CVE in the facts provided, but absence of documentation is not proof of safety. If you suspect compromise, isolate affected systems, preserve volatile evidence, follow CISA forensics triage expectations, rotate secrets that traversed the gateway, and review session and auth logs for abuse. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior public breach corpora while you complete incident response.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X