CVE-2026-88772 actively exploited: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CISA added CVE-2026-88772, a memory corruption in Citrix NetScaler, to its Known Exploited Vulnerabilities catalogue. It could allow for remote code execution or denial of service. Federal agencies must remediate by September 30, 2026.
Citrix identified a memory buffer flaw in NetScaler ADC and NetScaler Gateway. This improper restriction of operations permits remote code execution or denial of service attacks. The entry confirms active exploitation through the CISA Known Exploited Vulnerabilities catalogue. Organizations running unpatched Citrix NetScaler instances face this risk. Federal agencies must act within specific timelines outlined by regulatory bodies. The source notes that ransomware campaign usage remains unknown at this time. Administrators should apply vendor mitigations immediately. Compliance requires following CISA directives on prioritizing security updates based on risk. Cloud service providers must adhere to similar guidance or discontinue product use if fixes are unavailable. Each stakeholder must evaluate internet exposure of every asset. Federal entities must complete remediation by September 30, 2026.