CVE Digest

CVE Digest — September 27, 2026

  • Security Bulletin
3 CVE 2 KEV Critical

Digest for September 27, 2026: 2 new entries in the CISA KEV catalog and 1 advisory from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2026-88772 KEVCitrix NetScaler9.5CriticalCritical memory-buffer bounds flaw (CWE-119) in Citrix NetScaler ADC and Gateway enabling RCE or denial of service. Affects ADC/Gateway before 14.1-73.37 and 13.1-64.23, plus FIPS and NDcPP builds. CVSS 9.5. Known exploited; apply vendor mitigations per BOD 26-04.
CWE-119
CVE-2026-88771 KEVCitrix NetScaler9.5CriticalCritical improper input validation (CWE-20) in Citrix NetScaler ADC and Gateway letting an unauthenticated attacker run arbitrary commands. Affects ADC/Gateway before 14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP builds. CVSS 9.5. Known exploited; apply mitigations per BOD 26-04.
CWE-20
CVE-2026-88771–9.5CriticalACN advisory: Citrix released updates for NetScaler ADC and Gateway fixing 8 vulnerabilities, 3 critical and 5 high severity, including CVE-2026-88771 and CVE-2026-88772 with observed exploitation on unpatched systems. Apply updates urgently.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.