LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 27, 2026
CVSS 9.5 · Critical⚠ Actively exploited (CISA KEV)
9.5
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Sep 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on Sep 27, 2026, with a federal patch deadline of Sep 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

CVE-2026-88772 is a memory buffer bounds vulnerability in Citrix NetScaler ADC and NetScaler Gateway. Improper restriction of operations within a memory buffer can lead to remote code execution or denial of service, which matters because these products often sit at the network edge and handle authentication and application delivery for many organizations.

Public detail beyond the CISA summary is limited here. Confirm exact affected builds, fixed releases, and any configuration prerequisites against the vendor advisory before you act.

How it works

This issue is classified as CWE-119: improper restriction of operations within the bounds of a memory buffer. In products of this class, code that reads or writes memory does not correctly enforce size or boundary checks. An attacker who can reach the vulnerable processing path may supply input that causes the process to operate outside the intended buffer.

At a high level, successful abuse of such a flaw can corrupt memory in ways that crash the service (denial of service) or, in worse cases, allow execution of attacker-controlled code in the context of the affected process. The CISA summary states that remote code execution or denial of service is possible. Do not invent or assume specific packets, endpoints, or exploit steps; those details, if any, must come from the vendor advisory and your own controlled analysis.

Am I affected? How to find it in your systems

Citrix NetScaler ADC and NetScaler Gateway typically run as appliances or virtual appliances in DMZs, as reverse proxies, load balancers, SSL VPN / remote-access gateways, and application delivery controllers. Inventory every instance that terminates client or partner traffic, including HA pairs, clouds, and lab systems that may still be reachable.

How to remediate

Patch first. Apply the vendor update or mitigation package named in the official Citrix advisory for CVE-2026-88772. Follow CISA’s required action: apply mitigations in accordance with vendor instructions, ensure compliance with BOD 26-04 prioritization based on risk, and follow CISA’s forensics triage requirements where applicable. For cloud-hosted or managed instances, follow applicable BOD 26-04 cloud guidance. If mitigations are unavailable, discontinue use of the product as directed by that guidance.

If you can't patch immediately

Use compensating controls only as a bridge until the vendor fix is applied.

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to full compromise of the appliance and downstream access to applications or credentials. Known ransomware use is not documented for this CVE in the facts provided, but absence of documentation is not proof of safety. If you suspect compromise, isolate affected systems, preserve volatile evidence, follow CISA forensics triage expectations, rotate secrets that traversed the gateway, and review session and auth logs for abuse. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior public breach corpora while you complete incident response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · NetScaler
WeaknessCWE-119
CVSS base score9.5 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedSep 27, 2026
Added to CISA KEVSep 27, 2026
Federal patch deadlineSep 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities