Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
What happened
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
CISA lists it as exploited, added 27 Sep 2026.
Does it affect you
Names Citrix NetScaler ADC. Enter the product and version you run to place it against the affected range the vendor published.
What to do
- Follow the vendor advisory for the fixed release and any interim mitigation.
support.citrix.com - Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
cisa.gov
CISA’s notes for this entry:
- Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778
- support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
- BOD 26-04: cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- Forensics Triage Requirements: cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- nvd.nist.gov/vuln/detail/CVE-2026-88772
Affected, as published to NVD
- citrix-adc
- Citrix NetScaler ADC: 13.1 up to the fix in 13.1-64.23
The record
- NVD status
- Analyzed
- Published
- 27 Sep 2026, last modified 28 Sep 2026 (NVD)
- Severity
- CVSS 3.1 base score 8.1, High — computed here from the vector; NVD states 8.1.
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer (NVD; names by MITRE)
- Exploitation
- Listed in CISA’s Known Exploited Vulnerabilities catalogue since 27 Sep 2026; federal remediation due 30 Sep 2026. CISA entry
- Vendor
- Citrix · NetScaler (CISA)
References on the NVD record
- support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778Vendor Advisory
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772US Government Resource
Reporting that names this identifier
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) — Help Net Security, 1 d ago
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug — SecurityWeek, 1 d ago
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — CISA, 2 d ago
- CISA Adds Two Known Exploited Vulnerabilities to Catalog — CISA, 2 d ago
Sources
The verdict above is computed from the products and versions you entered and the affected ranges the vendor published to NVD. It does not inspect your environment, and this site never reports a product as unaffected: why.