www.cisa.gov 4 Oct 2026, 12:00 UTC

CISA Warns of Active Exploitation Targeting Citrix NetScaler Flaw

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added one vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The newly listed CVE is CVE-2026-88779, described as a Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability. Officials emphasise that this type of flaw is a common attack vector and poses significant risks to the federal enterprise. The update underscores the ongoing focus on rapidly remediating high‑risk vulnerabilities that have demonstrated real-world exploitation.

The announcement notes that the binding directive BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritise security updates for CVEs listed in the KEV Catalog on publicly exposed assets that grant an attacker total control after exploitation. While the directive applies to FCEB agencies, CISA advises all organisations to adopt risk‑based vulnerability management and to prioritise remediation of KEV‑listed vulnerabilities.

CISA also invites organisations to submit suspected exploited vulnerabilities for potential KEV listing via a nomination form, provided there is a CVE ID, evidence of exploitation, and clear mitigation guidance.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline