EchelonGraph verdictMitigate nowTreat as an emergency — this is being exploited.
- •1,735 internet-facing services (distinct ip:port) on record running an affected version — derived from Shodan data (© Shodan); a patched service can stay counted while its port stays open
- •Actively exploited in the wild (CISA-KEV)
CISA-KEV: ExploitedEPSS PROB: 1.3%CVSS: 8.1Exploit: cisa kev · ssvc active · public exploitExposed services: 1,735
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Internet exposure · derived from Shodan data
1,735 internet-facing services (distinct ip:port) on record running a version that maps to CVE-2026-88772, in our KEV-Exposure radar’s Shodan-derived sample.
across 25 countries (Germany, Australia, United States, Mauritius, United Kingdom)top: netscaler_gateway
See the KEV-Exposure radar →Derived from Shodan data. Shodan data is owned by Shodan, which holds its copyright (© Shodan). EchelonGraph claims no ownership of it or copyright in it. Aggregate, host-redacted. How it counts: every 12 hours, when Shodan query credits allow, the radar runs one Shodan query per tracked product, reads up to 100 ip:port services per query, and keeps a service when its banner version matches a CISA-KEV or high-EPSS CVE; a service is dropped when neither a search nor a Shodan InternetDB port re-check has refreshed it for 21 days. A re-check that finds the port still listed by Shodan InternetDB refreshes the service without re-reading the banner, so a patched service can stay counted while its port stays open. A count is a banner-version inference over a sample, not an exploit test and not an internet-wide census, and the unit is a service, not a machine: a machine answering on two ports counts twice.
CISA SSVCTrack at low, Attend at medium and Act at high mission impact.
No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low, sooner than that at medium and as soon as possible at high mission impact, and watch the vendor's advisory for the fix.
Exploitation active (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table