Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Is CVE-2026-88772 exploited?
Listed in the CISA KEV catalog on 2026-09-27.
Federal remediation due 2026-09-30.
Past that date by 1 days.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
Citrix Systems · NetScaler · ADC <14.1-73.37
Citrix Systems · NetScaler · Gateway <13.1-64.23
Citrix Systems · NetScaler · ADC NDcPP <13.1-37.279
Citrix Systems · NetScaler · ADC FIPS <14.1-73.37
Citrix Systems · NetScaler · Gateway <14.1-73.37
Citrix Systems · NetScaler · ADC <13.1-64.23
Citrix Systems · NetScaler · ADC FIPS <13.1-37.279