CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Summary
Citrix NetScaler ADC and NetScaler Gateway are affected by a vulnerability that allows for remote code execution or denial of service due to improper restriction of operations within a memory buffer. Defenders must apply mitigations as per vendor instructions and comply with CISA's guidance on prioritizing security updates.
IFF Assessment
This vulnerability allows for remote code execution or denial of service, posing a significant threat to affected systems and defenders.
Severity
The vulnerability allows for remote code execution and denial of service, with a high potential for exploitability and significant impact on confidentiality, integrity, and availability.
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in Citrix NetScaler products requires immediate attention from defenders. Organizations must prioritize applying vendor-provided mitigations and ensure their patching strategies align with CISA's risk-based guidance. The potential for remote code execution makes this a prime target for attackers.