CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2026-09-27. EPSS: 1.3% chance of exploitation in the next 30 days.

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Affected products

  • Citrix NetScaler Application Delivery Controller: from 13.1, before 13.1-64.23 (fixed in 13.1-64.23); from 13.1, before 13.1.37.279 (fixed in 13.1.37.279); from 14.1, before 14.1-73.37 (fixed in 14.1-73.37); from 14.1-66.68, up to and including 14.1-73.37
  • Citrix NetScaler Gateway: from 13.1, before 13.1-64.23 (fixed in 13.1-64.23); from 14.1, before 14.1-73.37 (fixed in 14.1-73.37)

Published 2026-09-27. Last modified 2026-09-28.