Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.5Security Advisory

TL;DR 📌

  • Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
  • Highest CVSS: 9.5 (Critical).
  • Listed in CISA KEV (2026-09-27) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-88772.

What it is

CVE-2026-88772 is a memory buffer boundary flaw in Citrix NetScaler ADC and NetScaler Gateway, classified as improper restriction of operations within the bounds of a memory buffer. Exploitation can lead to remote code execution or denial of service.

The CVSS 4.0 vector shows network attack vector, no privileges required, no user interaction, and impact across confidentiality, integrity and availability at the vulnerable, subsequent and application layers — consistent with an unauthenticated attacker reaching the flaw over the network and potentially executing code or crashing the device. Attack complexity is listed as high, so exploitation is not trivial even though no authentication or user interaction is needed.

Affected versions are: ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway before 14.1-73.37 and before 13.1-64.23.

This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-09-27. It is known to be exploited.

What to do

  • Identify all NetScaler ADC and NetScaler Gateway instances and check build numbers against the affected ranges above; anything below 14.1-73.37 or 13.1-64.23 (or the corresponding FIPS/NDcPP builds) is in scope.
  • Upgrade ADC to 14.1-73.37 or 13.1-64.23 or later; upgrade FIPS builds to 14.1-73.37 FIPS or 13.1.37.279 FIPS/NDcPP or later; upgrade Gateway to 14.1-73.37 or 13.1-64.23 or later.
  • Given the KEV listing, treat this as an active priority: patch internet-facing NetScaler Gateway and ADC management/data-plane interfaces first.
  • Where immediate patching isn’t possible, restrict network access to management and gateway interfaces to trusted sources only, as a temporary compensating control while upgrades are scheduled.
  • After patching, review NetScaler logs for anomalies predating the fix, and rotate any credentials or session secrets stored on affected appliances as a precaution.

For leadership 🧭

Executive summary. NetScaler ADC and Gateway appliances running builds below 14.1-73.37 or 13.1-64.23 (including the FIPS/NDcPP variants) can be remotely crashed or taken over by an unauthenticated attacker, and this is already listed as actively exploited. Given these devices typically sit at the network edge handling authentication and remote access, this needs to move to the top of the patching queue this week, not the next maintenance cycle.

Why it matters:

  • NetScaler Gateway is usually internet-facing and handles remote access authentication, so a working exploit here gives an outsider a direct path into the perimeter without needing any credentials.
  • The flaw affects memory handling in ADC and Gateway itself, meaning a successful attack can either execute code on the appliance or simply crash it, taking down load balancing or VPN access for everyone behind it.
  • CISA’s KEV listing confirms exploitation is already happening, so unpatched, internet-reachable instances are a live target rather than a theoretical risk.
  • FIPS and NDcPP builds are separately versioned and easy to miss during a routine version check, leaving compliance-mandated deployments exposed if only the standard build numbers are checked.

Now / Next / Later:

  • Now: Inventory every NetScaler ADC and Gateway instance and record its exact build number against the affected ranges to identify what is exposed right now.
  • Next: Patch all in-scope appliances to 14.1-73.37 or 13.1-64.23 (or the matching FIPS/NDcPP builds) in the next available change window, prioritising internet-facing Gateway and ADC interfaces first.
  • Later: Restrict management and gateway interfaces to trusted source ranges by default, review NetScaler logs for anomalies from before the patch, and rotate credentials or session secrets stored on the appliances as standard post-patch hygiene.

Source