CISA KEV Alert 4 Oct 2026, 20:00 UTC

CISA Warns of Active Exploitation in Citrix NetScaler Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalogue on 4 October 2026. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway, formerly known as Citrix ADC and Citrix Gateway. It is an improper restriction of operations within the bounds of a memory buffer that could allow denial of service.

The vulnerability is a memory-buffer bounds issue with a CVSS score of 8.7, rated High. The available data identifies denial of service as the potential impact but does not provide further attack-vector details. Patch availability is currently unknown. Citrix has published guidance relating to the vulnerability, but no patch advisory was provided in the supplied data.

CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. The data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate CVE-2026-88779 by 7 October 2026.

CISA requires agencies to apply mitigations in accordance with vendor instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching requirements. All organisations should review their Citrix NetScaler exposure and apply the vendor’s available mitigations.

See the NVD entry and CISA KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-88779.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline