Junglewise Threat Intelligence

CVE-2026-88772: Citrix NetScaler ADC and Gateway remote code execution and denial of service

CVE-2026-88772 · Severity: critical · Exploited in the wild · Published 2026-09-27

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway, Citrix NetScaler. Vendors: Citrix.

Executive brief

Citrix NetScaler ADC and NetScaler Gateway are network appliances that manage traffic and provide secure access to corporate applications. A vulnerability in these products can allow attackers to remotely execute arbitrary code or crash the appliance, potentially compromising network availability and exposing sensitive data.

Technical details

The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway across multiple versions, enabling remote code execution or denial of service. An attacker with network access to the affected appliance can exploit this issue to execute arbitrary code or disrupt service. Patches are available in versions 14.1-73.37, 13.1-64.23, and their FIPS variants.

Affected products

  • Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
  • Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23

Timeline

  • 2026-09-27: disclosed

References

Related threats