peter bassill · operator
$ cve CVE-2026-88772 JSON

CVE-2026-88772 KEV

?
unscored · CVSS

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-30.

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Scoring

CVSSunscored
EPSS—
WeaknessCWE-119
On CISA KEVyes — remediate by 2026-09-30
Public exploitnone known
Published2026-09-27
Last modified2026-09-27

CISA KEV

NameCitrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added2026-09-27
Due2026-09-30
Vendor / productCitrix / NetScaler
Ransomware usenone reported

References

→ the Explorer  ·  watch your stack  ·  NVD