HIGH Actively Exploited

⚠️ CVE-2026-88772: New Actively Exploited Vulnerability Added to CISA KEV

21 views

CVE-2026-88772 is an actively exploited vulnerability listed in the CISA KEV catalog patching is recommended.

Overview

CVE-2026-88772 has been added to the CISA Known Exploited Vulnerabilities catalog. Published on September 27, 2026. Threat actors are actively exploiting this vulnerability in real-world attacks.

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

Threat Intelligence

Metric Value
CVE ID CVE-2026-88772
Severity HIGH
CVSS Score 0.0/10
CISA KEV ✅ Yes — Actively Exploited
KEV Date Added September 27, 2026
Remediation Deadline September 30, 2026

Why This Matters

This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, which means threat actors are actively exploiting it in real-world attacks.

Federal agencies are required to remediate by September 30, 2026. All organizations should treat this deadline as a strong recommendation.

CISA Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778 ; https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 ; https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-88772

Recommended Actions

  1. Verify exposure — Determine if your environment uses the affected software.
  2. Apply patches — Update to the latest version as soon as a fix is available.
  3. Monitor for compromise — Check logs for unusual activity.
  4. Meet the deadline — CISA recommends remediation by September 30, 2026.

References


CVE data aggregated from the National Vulnerability Database (NVD), CISA Known Exploited Vulnerabilities catalog, and FIRST EPSS. Analysis updated as new intelligence becomes available. Last updated: 2026-09-27.

Are you affected by CVE-2026-88772?

Run a free ThreatSpot scan to check if your site is vulnerable.

Starting scan...

Related Alerts