CVE-2026-88772

CRITICAL CISA KEV POC TTE Zero-Day Pub 27/09 Upd 28/09

Overview

This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.

Vulnerability Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Impact

An attacker can exploit this vulnerability remotely without any authentication or user interaction to execute arbitrary code on the affected system or cause a denial of service by crashing the service. This enables full system compromise, including potential unauthorized access to sensitive data and lateral movement within the network. The ability to execute code at the system level can lead to persistent control over the appliance, severely impacting business continuity and security posture.

Solution

Citrix has released security updates addressing this vulnerability in NetScaler ADC and Gateway versions 14.1-73.37 and 13.1-64.23, including patches for FIPS and NDcPP builds. Administrators should apply these specific version upgrades as detailed in Citrix Security Bulletin CTX697096. The advisory provides comprehensive patch installation instructions and recommended mitigation steps. Refer to the official Citrix support article for exact patch versions and deployment guidance.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (1)

Repository Author Stars Forks Date Link
murrez/CVE-2026-88772
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build v...
murrez 2 0 2026-09-27 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

6 events
2026-09-28
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-09-27
Threat Sensor Sighting — Considerable activity

Sighting activity recorded

2026-09-27
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-09-27
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: Citrix, product: NetScaler ADC and NetScaler Gateway

2026-09-27
PoC Published (1 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (3364 sightings)

Active exploitation confirmed with 3364 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Remote Code Execution
100% rce
Code Injection
71% code_injection
Buffer Overflow
69% buffer_overflow
OS Command Injection
61% command_injection

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-44 Overflow Binary Resource File
76%
High Very High
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
43%
High High
CAPEC-14 Client-side Injection-induced Buffer Overflow
43%
Medium High
CAPEC-123 Buffer Manipulation
33%
High Very High
CAPEC-8 Buffer Overflow in an API Call
33%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-88772
support.citrix.com
GitHub CVE
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772