CISA has added CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway and is an improper restriction of operations within the bounds of a memory buffer that could permit remote code execution or denial of service.
The flaw is a memory-buffer handling vulnerability that can be exploited remotely. Successful exploitation may allow an attacker to execute code or disrupt service. NVD assigns the vulnerability a CVSS score of 9.5, rated Critical. Patch availability is currently unknown. Citrix has published mitigation and forensic guidance, but no patch advisory was provided in the supplied data.
KEV inclusion confirms that attackers are actively exploiting the vulnerability. The available data does not confirm use in ransomware campaigns. CISA has set 30 September 2026 as the remediation deadline. Organisations should also review Citrix’s indicators of compromise and conduct forensic triage in accordance with the relevant CISA guidance.
CISA requires affected stakeholders to apply mitigations in accordance with Citrix’s instructions and comply with BOD 26-04, “Prioritizing Security Updates Based on Risk”, including its requirements for cloud services. Organisations should discontinue use of the product if mitigations are unavailable, evaluate each asset’s internet exposure and follow applicable BOD 26-04 patching requirements. Federal Civilian Executive Branch (FCEB) agencies are directly subject to this directive, but all organisations should review their exposure.
See the linked NVD entry and CISA KEV catalogue for full details.