What it is
CVE-2026-88772 is an unauthenticated vulnerability affecting Citrix NetScaler ADC, Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before...
Vulnerability report
ADC Remote Code Execution
Citrix NetScaler / ADC · affected before 14.1-73.37
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-88772 is an unauthenticated vulnerability affecting Citrix NetScaler ADC, Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Citrix NetScaler / ADC affected before 14.1-73.37.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Citrix
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Citrix First | 2026-09-27 16:45 UTC |
| CVE | 2026-09-27 20:40 UTC |
| Tenable Blog | 2026-09-27 21:21 UTC |
| CISA | 2026-09-27 21:50 UTC |
| The Hacker News | 2026-09-28 07:30 UTC |
| CERT Polska | 2026-09-28 08:21 UTC |
| Rapid7 | 2026-09-28 10:21 UTC |
| NCSC Alerts and Advisories | 2026-09-28 12:20 UTC |
| Palo Alto Unit42 | 2026-09-28 15:21 UTC |
| Qualys ThreatPROTECT | 2026-09-28 16:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
—
Recent mention · The Record
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Read full advisoryCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · The Record
US, UK warn of exploited Citrix NetScaler zero-day bugsThe Record · 28 Sep 2026
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Recent mention · Qualys ThreatPROTECT
Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)Qualys ThreatPROTECT · 28 Sep 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to secure their systems against two critical Citrix NetScaler vulnerabilities that have been exploited in attacks. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before September 30, 2026. CVE-2026-88771 This is an improper input validation … Continue reading "Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)"
Recent mention · Palo Alto Unit42
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the WildPalo Alto Unit42 · 28 Sep 2026
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.
Recent mention · NCSC Alerts and Advisories
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler GatewayNCSC Alerts and Advisories · 28 Sep 2026
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Recent mention · Rapid7
Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772Rapid7 · 28 Sep 2026
OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack...
Recent mention · TheRegister
Certainties in life: Death, taxes, and critical Citrix vulns under attackTheRegister · 28 Sep 2026
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
Recent mention · The Hacker News
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws GloballyThe Hacker News · 28 Sep 2026
Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer...
Recent mention · Security Affairs
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-DaySecurity Affairs · 27 Sep 2026
Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]
Recent mention · NCSC Security Advisories
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler GatewayNCSC Security Advisories · 27 Sep 2026
Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties die gebruikmaken van NetScaler-instances zijn ook kwetsbaar voor deze kwetsbaarheden. Deze...
Recent mention · Citrix
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778Citrix · 27 Sep 2026
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes. Citrix has released updates for...
Recent mention · CERT Polska
Podatności 0-day w urządzeniach Citrix NetScalerCERT Polska · 27 Sep 2026
Zespół CERT Polska informuje o dwóch podatnościach 0-day w urządzeniach Citrix NetScaler, które są aktywnie wykorzystywane do ataków.Na podstawie dostępnych informacji należy założyć, że podatności umożliwiają zdalnemu, nieuwierzytelnionemu atakującemu wykonanie dowolnego kodu na urządzeniu. Szczegóły techniczne nie zostały jeszcze ujawnione, a producent nie opublikował aktualizacji bezpieczeństwa.Z uwagi na aktywnie wykorzystywane luki i brak dostępnej poprawki, rekomendujemy odłączenie urządzeń NetScaler od Internetu oraz śledzenie oficjalnych komunikatów producenta.Biuletyny...
Recent mention · Tenable Blog
Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesTenable Blog · 27 Sep 2026
CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-09-28 09:58:16 UTC · 0 stars · AI assessment 85%
CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)
github · Created 2026-09-27 20:24:56 UTC · 1 stars · AI assessment 85%
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS probe. CTX697096; active exploitation reported. https://pocbit.org/pocs/cve-2026-88772
Timeline
16:20 UTC
Exploitation attested by an external source
15:21 UTC
Exploitation attested by an external source
12:20 UTC
Exploitation attested by an external source
10:21 UTC
Exploitation attested by an external source
08:21 UTC
Exploitation attested by an external source
07:30 UTC
Exploitation attested by an external source
21:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
21:21 UTC
Exploitation attested by an external source
20:40 UTC
Exploitation attested by an external source
20:24 UTC
Public proof-of-concept code published
16:45 UTC
High-confidence, third-party attested exploitation
16:09 UTC
Vulnerability disclosed publicly
07:14 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-88772
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-88772",
"confidence": "Confirmed",
"cvss_score": 9.5,
"cvss_estimated": false,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}