CISA's list that day

27 September 2026

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Citrix NetScaler. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01