Skip to content

CVE-2026-88772

Citrix NetScaler ADC and Gateway memory overflow enables remote code execution or denial of service (CVE-2026-88772)

Critical 9.5 KEV Published

Citrix NetScaler ADC and Gateway have a critical memory overflow (CVE-2026-88772) allowing unauthenticated remote code execution or denial of service. CISA KEV lists it as exploited. Update to fixed builds: ADC 14.1-73.37, 13.1-64.23; Gateway 14.1-73.37, 13.1-64.23.

What happened

Citrix NetScaler ADC and Citrix NetScaler Gateway contain a memory overflow flaw classified as CWE-119. An attacker can trigger the vulnerability over the network without authentication and without any action by a user. Successful exploitation can lead to remote code execution or denial of service. The CVSS v4.0 score is 9.5, rated critical, with high impact to both the vulnerable system and subsequent systems.

CISA added CVE-2026-88772 to the Known Exploited Vulnerabilities catalog on 27 September 2026. CISA's SSVC assessment describes exploitation as active, and the KEV entry lists the vulnerability as exploited.

Who is affected

Affected products are:

  • ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP.
  • Gateway before 14.1-73.37 and before 13.1-64.23.

If you run these products as internet-facing application delivery or remote access infrastructure, check the running version against the fixed builds below.

What to do now

  1. Apply the vendor's fixed builds. For ADC, update to 14.1-73.37 or 13.1-64.23; for ADC FIPS and NDcPP, update to 14.1-73.37 FIPS or 13.1.37.279 FIPS and NDcPP. For Gateway, update to 14.1-73.37 or 13.1-64.23.
  2. Prioritise appliances that are reachable from the internet. CISA's required action directs organisations to evaluate internet exposure and follow BOD 26-04 guidance; the KEV due date is 30 September 2026.
  3. If a fixed build cannot be applied immediately, follow CISA's BOD 26-04 guidance and discontinue use of the product where mitigations are unavailable.
  4. Confirm that affected instances are updated and no longer report a vulnerable version.

Beyond the patch

This is an internet-exposed appliance under active exploitation, so detection and exposure review should run alongside patching. Managed Detection & Response (MDR) can monitor for post-exploitation activity on affected NetScaler instances, and Virtual CISO Services (vCISO) can help inventory exposed appliances and plan a BOD 26-04-aligned response.

Affected and fixed versions

ProductAffectedFixed in
ADC– < 14.1-73.37
– < 13.1-64.23
– < 14.1-73.37 FIPS
– < 13.1.37.279 FIPS and NDcPP
14.1-73.37
13.1-64.23
14.1-73.37 FIPS
13.1.37.279 FIPS and NDcPP
Gateway– < 14.1-73.37
– < 13.1-64.23
14.1-73.37
13.1-64.23

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.