ZeroDayAlert

CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Citrix NetScaler Added to KEV 2026-09-27 Federal due 2026-09-30 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Citrix NetScaler ADC and NetScaler Gateway deployments are vulnerable to a memory buffer bounds issue that permits remote code execution or denial of service. The record does not specify which versions of NetScaler are affected, nor does it detail whether the vulnerability requires authentication or network proximity to exploit.

How to check whether this touches you

  • Inventory your Citrix products: confirm whether you operate NetScaler ADC, NetScaler Gateway, or both, and in what deployment mode (on-premises, cloud-hosted, or hybrid).
  • Establish network reachability: determine whether your NetScaler instances are accessible from the internet or from untrusted internal networks, or whether they are air-gapped and accessible only to defined administrators.
  • Identify running versions: extract the firmware version from each appliance (visible in the management console or via SSH), noting that version numbers alone do not confirm patch status—Citrix may backport fixes into maintenance releases.
  • Check vendor communications: review Citrix security bulletins and advisories for specific affected version ranges and patched builds.

What to do

  1. Obtain the latest Citrix security advisory for CVE-2026-88772 and confirm which NetScaler versions require action and which patches are available.
  2. If your instances are internet-facing or reachable from untrusted networks and you cannot patch immediately, restrict network access to the NetScaler management and data planes using firewall rules, network segmentation, or access control lists until a patch is deployed.
  3. Prioritise patching in accordance with CISA BOD 26-04 guidance: apply patches to internet-exposed instances first, then to internal-only appliances according to your risk assessment.
  4. If no patch is available from Citrix and mitigations are insufficient, evaluate whether discontinuation of the product or migration to an alternative solution is necessary under BOD 26-04 compliance requirements.
  5. Enable logging of all connections and administrative actions on affected NetScaler instances, and retain logs for forensic analysis.
  6. Escalate to your security team and incident response plan if you discover evidence of exploitation or unauthorised access.

If you find you were exposed

Exploitation of memory buffer vulnerabilities typically occurs before public disclosure, so assume any appliance with internet exposure or access from potentially compromised networks may have been targeted. Examine NetScaler audit logs and syslog records for suspicious administrative sessions, configuration changes, or unexpected process execution dating back several months before the CISA advisory date. Log retention constraints often limit retrospective visibility; prioritise preservation of any logs that predate the advisory by at least 90 days.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-88772 is being exploited. It cannot tell you whether NetScaler is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →