HIGHVulnerability
Verified
Global

CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Analysis

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-27. Remediation due: 2026-09-30.

Indicators of Compromise (1)

CVE (1)
CVE-2026-88772
Source Attribution

Originally published by CISA KEV on Sep 27, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-15896 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au

CVE-2026-15896
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-19660 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass ...

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled

CVE-2026-19660
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

CVE-2026-14378
NIST NVD