Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-88772

ADC Remote Code Execution

Citrix NetScaler / ADC · affected before 14.1-73.37

Severity
CVSS 9.5 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
—
First observed
—
Last observed
—

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-88772 is an unauthenticated vulnerability affecting Citrix NetScaler ADC, Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Citrix NetScaler / ADC affected before 14.1-73.37.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Citrix NetScaler Affected
ADC
Before 14.1-73.37 Before 13.1-64.23 Before 14.1-73.37 FIPS Before 13.1.37.279 FIPS and NDcPP
Citrix NetScaler Affected
Gateway
Before 14.1-73.37 Before 13.1-64.23
Published
27 Sep 2026
Exploitation Reported
27 Sep 2026
Attack vector
Remote
Complexity
High
Privileges
None
User interaction
None

Tags

cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Citrix

Recorded 27 Sep 2026

A trusted third party reported exploitation.

Proof of concept available

GitHub

Recorded 27 Sep 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Citrix First 2026-09-27 16:45 UTC
CVE 2026-09-27 20:40 UTC
Tenable Blog 2026-09-27 21:21 UTC
CISA 2026-09-27 21:50 UTC
The Hacker News 2026-09-28 07:30 UTC
CERT Polska 2026-09-28 08:21 UTC
Rapid7 2026-09-28 10:21 UTC
NCSC Alerts and Advisories 2026-09-28 12:20 UTC
Palo Alto Unit42 2026-09-28 15:21 UTC
Qualys ThreatPROTECT 2026-09-28 16:20 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v4.0

9.5 Critical
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

EPSS

—

Recent mention · The Record

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

Read full advisory

All CVSS Scores

CVSS v4.0 9.5 Critical

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS v3.1 8.1 High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

All Mentions

Recent mention · The Record

US, UK warn of exploited Citrix NetScaler zero-day bugs

The Record · 28 Sep 2026

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

Recent mention · Qualys ThreatPROTECT

Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)

Qualys ThreatPROTECT · 28 Sep 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to secure their systems against two critical Citrix NetScaler vulnerabilities that have been exploited in attacks. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before September 30, 2026. CVE-2026-88771 This is an improper input validation … Continue reading "Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)"

Recent mention · Palo Alto Unit42

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Palo Alto Unit42 · 28 Sep 2026

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

Recent mention · NCSC Alerts and Advisories

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

NCSC Alerts and Advisories · 28 Sep 2026

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Recent mention · Rapid7

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Rapid7 · 28 Sep 2026

OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack...

Recent mention · TheRegister

Certainties in life: Death, taxes, and critical Citrix vulns under attack

TheRegister · 28 Sep 2026

Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes

Recent mention · The Hacker News

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News · 28 Sep 2026

Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer...

Recent mention · Security Affairs

Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Security Affairs · 27 Sep 2026

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]

Recent mention · NCSC Security Advisories

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

NCSC Security Advisories · 27 Sep 2026

Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties die gebruikmaken van NetScaler-instances zijn ook kwetsbaar voor deze kwetsbaarheden. Deze...

Recent mention · Citrix

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778

Citrix · 27 Sep 2026

Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes. Citrix has released updates for...

Recent mention · CERT Polska

Podatności 0-day w urządzeniach Citrix NetScaler

CERT Polska · 27 Sep 2026

Zespół CERT Polska informuje o dwóch podatnościach 0-day w urządzeniach Citrix NetScaler, które są aktywnie wykorzystywane do ataków.Na podstawie dostępnych informacji należy założyć, że podatności umożliwiają zdalnemu, nieuwierzytelnionemu atakującemu wykonanie dowolnego kodu na urządzeniu. Szczegóły techniczne nie zostały jeszcze ujawnione, a producent nie opublikował aktualizacji bezpieczeństwa.Z uwagi na aktywnie wykorzystywane luki i brak dostępnej poprawki, rekomendujemy odłączenie urządzeń NetScaler od Internetu oraz śledzenie oficjalnych komunikatów producenta.Biuletyny...

Recent mention · Tenable Blog

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · 27 Sep 2026

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

FollowerSeize/CVE-2026-88772-POC

github · Created 2026-09-28 09:58:16 UTC · 0 stars · AI assessment 85%

CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)

murrez/CVE-2026-88772

github · Created 2026-09-27 20:24:56 UTC · 1 stars · AI assessment 85%

CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation reported. https://pocbit.org/pocs/cve-2026-88772

Timeline

From disclosure to observed exploitation

  1. 16:20 UTC

    KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  2. 15:21 UTC

    KEV confirmed by Palo Alto Unit42

    Exploitation attested by an external source

  3. 12:20 UTC

    KEV confirmed by NCSC Alerts and Advisories

    Exploitation attested by an external source

  4. 10:21 UTC

    KEV confirmed by Rapid7

    Exploitation attested by an external source

  5. 08:21 UTC

    KEV confirmed by CERT Polska

    Exploitation attested by an external source

  6. 07:30 UTC

    KEV confirmed by The Hacker News

    Exploitation attested by an external source

  7. 21:50 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  8. 21:21 UTC

    KEV confirmed by Tenable Blog

    Exploitation attested by an external source

  9. 20:40 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  10. 20:24 UTC

    Public PoC available

    Public proof-of-concept code published

  11. 16:45 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  12. 16:09 UTC

    CVE published

    Vulnerability disclosed publicly

  13. 07:14 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-88772

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-88772",
  "confidence": "Confirmed",
  "cvss_score": 9.5,
  "cvss_estimated": false,
  "epss_score": null,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}