## Overview
Citrix disclosed a critical vulnerability in its NetScaler ADC and Gateway products, identified as CVE-2026-88772. This vulnerability has a CVSS score of 9.5, indicating its high severity. It allows for remote code execution or denial of service, posing a significant risk to affected systems.
## Technical Details
The vulnerability affects multiple versions of Citrix NetScaler ADC and Gateway. Specifically, it impacts ADC versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP. Similarly, Gateway versions before 14.1-73.37 and 13.1-64.23 are also vulnerable. Attackers can exploit this flaw to execute arbitrary code or disrupt service availability.
## Impact
Organizations using the affected versions of Citrix NetScaler ADC and Gateway are at risk. Exploitation can lead to unauthorized access, data breaches, or service outages. The potential for remote code execution makes this vulnerability particularly dangerous, as it could allow attackers to take full control of the affected systems.
## Mitigation
Defenders should prioritize applying the latest patches provided by Citrix. Upgrading to the fixed versions is essential to mitigate the risks associated with CVE-2026-88772. Organizations should also review their security policies and monitor for any unusual activity that may indicate exploitation attempts.
CSURFACE Threat Sensor