CVE Digest — September 27, 2026
3 CVE
2 KEV
Critical
Digest for September 27, 2026: 2 new entries in the CISA KEV catalog and 1 advisory from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-88772 KEV | Citrix NetScaler | 9.5 | Critical | Critical memory-buffer bounds flaw (CWE-119) in Citrix NetScaler ADC and Gateway enabling RCE or denial of service. Affects ADC/Gateway before 14.1-73.37 and 13.1-64.23, plus FIPS and NDcPP builds. CVSS 9.5. Known exploited; apply vendor mitigations per BOD 26-04. CWE-119 | |
| CVE-2026-88771 KEV | Citrix NetScaler | 9.5 | Critical | Critical improper input validation (CWE-20) in Citrix NetScaler ADC and Gateway letting an unauthenticated attacker run arbitrary commands. Affects ADC/Gateway before 14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP builds. CVSS 9.5. Known exploited; apply mitigations per BOD 26-04. CWE-20 | |
| CVE-2026-88771 | – | 9.5 | Critical | ACN advisory: Citrix released updates for NetScaler ADC and Gateway fixing 8 vulnerabilities, 3 critical and 5 high severity, including CVE-2026-88771 and CVE-2026-88772 with observed exploitation on unpatched systems. Apply updates urgently. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.