The Exploit Bulletin

Archives
Log in
Subscribe
September 28, 2026

The Exploit Bulletin — Monday, September 28, 2026: 1 issue requires action

Monday, September 28, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: Citrix NetScaler ADC/Gateway


1. Unauthenticated memory-corruption RCE in Citrix NetScaler ADC and Gateway (CVE-2026-88772)

CISA KEV (due 2026-09-30) · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.5

Citrix shipped fixes in CTX697096 on 2026-09-27 and CISA added CVE-2026-88771 and CVE-2026-88772 to KEV the same day with a 2026-09-30 remediation deadline after confirming attacks on unpatched appliances, so a team that leaves an internet-facing NetScaler on a vulnerable build is exposed to compromise of its remote-access gateway.

An improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and NetScaler Gateway lets a remote, unauthenticated attacker execute code on the appliance or crash it. Citrix fixed it in bulletin CTX697096 alongside a second exploited zero-day, CVE-2026-88771 (improper input validation), and six further issues.

Affected: Citrix NetScaler ADC < 14.1-73.37; Citrix NetScaler ADC < 13.1-64.23; Citrix NetScaler ADC < 14.1-73.37 FIPS; Citrix NetScaler ADC < 13.1-37.279 FIPS and NDcPP; Citrix NetScaler Gateway < 14.1-73.37; Citrix NetScaler Gateway < 13.1-64.23

How to Test: Check the running NetScaler build on every ADC and Gateway appliance (including FIPS/NDcPP builds) against the fixed releases 14.1-73.37, 13.1-64.23 and 13.1-37.279 FIPS/NDcPP; anything older is vulnerable. Because exploitation preceded the patch, treat exposed appliances as potentially compromised: follow Citrix's CTX694799 'Steps to Take if NetScaler ADC is Suspected to be Compromised' and CISA's Forensics Triage Requirements referenced in the KEV entry, review appliance logs for unexpected crashes or restarts and unfamiliar files or accounts, and rotate credentials and sessions terminated through the gateway if anything looks off.

How to Patch: Upgrade NetScaler ADC and NetScaler Gateway to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP per CTX697096. If an upgrade cannot happen immediately, CISA's required action is to discontinue use of the product, i.e. take the appliance offline or remove its internet exposure until it is patched.

Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · CERT-EU 2026-014: Citrix confirmed active exploitation · CISA alert: zero-days exploited in NetScaler ADC, Gateway · Canadian Cyber Centre AL26-024

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Tuesday, September 29, 2026: 1 issue requires action Older → The Exploit Bulletin — Sunday, September 27, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.