Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-88772

Citrix NetScaler ADC/Gateway RCE via Memory Buffer Mishandling

Citrix NetScaler ADC and Gateway memory buffer flaw allows remote code execution or denial of service; actively exploited and CISA KEV listed.

cat cve-2026-88772.json
Vendor
Citrix
Product
NetScaler ADC, NetScaler Gateway
CVSS
N/A
EPSS (exploit probability)
N/A
Status
kev
CISA patch-by (BOD 22-01)
Published

CVE-2026-88772 is a memory buffer boundary violation in Citrix NetScaler ADC and NetScaler Gateway. Exploitation can lead to remote code execution or denial of service.

Like CVE-2026-88771, this flaw was exploited in the wild before Citrix released patches or assigned a CVE ID. CISA added it to the Known Exploited Vulnerabilities catalog on September 27, 2026, with a federal patching deadline of September 30, 2026. Citrix confirmed the CVE and released patches on September 28, 2026.

What to do: Apply the Citrix-supplied patches immediately. Check the Citrix security advisory for specific patched build versions. Investigate appliance logs for signs of prior compromise before patching. See the NVD record and CISA KEV catalog for primary source details.