CISA Adds CVE-2026-88772 in Citrix NetScaler
CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC
CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC and Gateway. The case joins CVE-2026-5430, which affects WSO2 products and was also added for active exploitation.
CISA added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog after confirming active exploitation against Citrix NetScaler ADC and Gateway. The flaw joins CVE-2026-5430, which was also added for active exploitation and is tied to WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
What is known about the activity against Citrix NetScaler?
CISA added CVE-2026-88772 to the KEV catalog because of active exploitation, and Cybersecurity Dive reported that exploitation began days before the public notice. That report also said the activity involved CVE-2026-88771, a remote code execution vulnerability.
Palo Alto Networks Unit 42 described CVE-2026-88772 as a memory overflow in the DTLS configuration of NetScaler ADC and Gateway, with the potential for remote code execution or denial of service. Wiz said the affected versions include branches earlier than 14.1-73.37 and 13.1-64.23, for both NetScaler ADC and Gateway.
What happened with WSO2?
CISA also added CVE-2026-5430 to the KEV catalog for active exploitation, and the flaw affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. According to CiberPlaneta, the bulletin for that alert corresponds to a path traversal and RCE case.
WSO2 told The Hacker News that it had alerted customers and delivered security updates on April 6, 2026, before publishing its advisory on May 3, 2026. That places the vendor response before the public release of the notice.
Why does this matter for the region?
Both alerts point to products widely used in corporate environments across Latin America, and the available material also shows active exploitation before the notices became public. In the Citrix case, exploitation began days before the alert, while in the WSO2 case the company says it distributed patches weeks before its advisory.
For NetScaler, the research also helps define the technical scope of the flaw and the affected versions. For WSO2, the key point is its addition to the KEV catalog for active exploitation and the confirmation that the vendor had already communicated and delivered updates.
Sources
- CVE-2026-88772 Impact, Exploitability, and Mitigation Stepswiz.io· Wiz
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772unit42.paloaltonetworks.com· Unit 42, Palo Alto Networks
- Alerta de Seguridad: Citrix NetScaler - RCE y denegación de ...ciberplaneta.org· CiberPlaneta
- CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacksbleepingcomputer.com· BleepingComputer
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVthehackernews.com· The Hacker News
- Alerta de Seguridad: WSO2 - Path Traversal y RCE | Boletín de Seguridad CiberPlanetaciberplaneta.org· CiberPlaneta
- Active Exploitation of Check Point Security Gateway and ...truesec.com· Truesec
- Citrix NetScaler exploitation began days before public notificationcybersecuritydive.com· Cybersecurity Dive



