CVE-2026-88772 is a memory overflow in Citrix NetScaler ADC and Citrix NetScaler Gateway that can yield remote code execution or denial of service. NVD rates it 9.5 critical (CVSS 4.0). Citrix notes it is reachable wherever DTLS is enabled — which is the default on VPN virtual servers — and confirmed active exploitation when it published security bulletin CTX697096. Affected builds are ADC before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1.37.279 FIPS and NDcPP, and Gateway before 14.1-73.37 and 13.1-64.23. CISA added it to the Known Exploited Vulnerabilities catalogue on 27 September, the same day as CVE-2026-88771, citing reports and partner threat intelligence confirming global exploitation. It is one of eight vulnerabilities fixed by the bulletin.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-88772 |
| CVSS | 9.5 (critical) |
| Vendor / product | Citrix NetScaler ADC / Gateway |
| Reported | 2026-09-28 |