CiberLATAMbywhalemate

CISA Adds CVE-2026-88772 in Citrix NetScaler

CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC and Gateway. The case joins CVE-2026-5430, which affects WSO2 products and was also added for active exploitation.

CISA added CVE-2026-88772 to its Known Exploited Vulnerabilities catalog after confirming active exploitation against Citrix NetScaler ADC and Gateway. The flaw joins CVE-2026-5430, which was also added for active exploitation and is tied to WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway.

What is known about the activity against Citrix NetScaler?

CISA added CVE-2026-88772 to the KEV catalog because of active exploitation, and Cybersecurity Dive reported that exploitation began days before the public notice. That report also said the activity involved CVE-2026-88771, a remote code execution vulnerability.

Palo Alto Networks Unit 42 described CVE-2026-88772 as a memory overflow in the DTLS configuration of NetScaler ADC and Gateway, with the potential for remote code execution or denial of service. Wiz said the affected versions include branches earlier than 14.1-73.37 and 13.1-64.23, for both NetScaler ADC and Gateway.

What happened with WSO2?

CISA also added CVE-2026-5430 to the KEV catalog for active exploitation, and the flaw affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. According to CiberPlaneta, the bulletin for that alert corresponds to a path traversal and RCE case.

WSO2 told The Hacker News that it had alerted customers and delivered security updates on April 6, 2026, before publishing its advisory on May 3, 2026. That places the vendor response before the public release of the notice.

Why does this matter for the region?

Both alerts point to products widely used in corporate environments across Latin America, and the available material also shows active exploitation before the notices became public. In the Citrix case, exploitation began days before the alert, while in the WSO2 case the company says it distributed patches weeks before its advisory.

For NetScaler, the research also helps define the technical scope of the flaw and the affected versions. For WSO2, the key point is its addition to the KEV catalog for active exploitation and the confirmation that the vendor had already communicated and delivered updates.

Sources

View all