CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks
CISA added actively exploited Citrix NetScaler CVE-2026-88779, an unauthenticated denial-of-service flaw, to the KEV catalog.
CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026, citing active exploitation. The high-severity Citrix NetScaler ADC and Gateway flaw (CVSS v4 8.7, CWE-119) lets an unauthenticated remote attacker cause a denial of service. Affected releases include builds before 14.1-73.41 and 13.1-64.28, plus specified FIPS versions. Federal civilian agencies must remediate by October 7, 2026 under BOD 26-04; ransomware use is listed as unknown.
- CVE-2026-88779 is a memory-bounds flaw enabling unauthenticated remote denial of service.
- CVSS v4 score is 8.7; no privileges or user interaction are required.
- CISA added it to KEV on October 4 with a federal deadline of October 7.
- ADC and Gateway builds before 14.1-73.41 and 13.1-64.28 are affected.
- CISA says ransomware use with this vulnerability is unknown.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article393 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779, a high-severity vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.
Tracked as CVE-2026-88779, this vulnerability involves an improper restriction of operations within the bounds of a memory buffer, also referred to as CWE-119. It can allow an unauthenticated, remote attacker to trigger a denial-of-service condition on vulnerable NetScaler appliances.
Citrix NetScaler Flaw
NetScaler has assigned the flaw a CVSS v4 score of 8.7, categorizing it as High. The CVSS vector indicates that exploitation is network-accessible and requires low attack complexity, no privileges, and no user interaction. The primary impact reported is on system availability.
CISA included this vulnerability in its KEV Catalog on October 4, 2026, mandating that U.S. federal civilian executive branch agencies remediate the issue by October 7, 2026.
The agency advises organizations to implement vendor mitigations under CISA’s Binding Operational Directive 26-04, which prioritizes remediation based on risk and requires forensic triage for affected assets.
The vulnerability affects multiple NetScaler ADC releases, including versions before 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282. Additionally, NetScaler Gateway deployments running versions earlier than 14.1-73.41 or 13.1-64.28 are also at risk.
Organizations operating internet-facing NetScaler infrastructure should promptly identify exposed ADC and Gateway instances, verify their installed versions, and upgrade to the corrected releases.
Security teams should also examine appliance logs, administrative access activity, configuration changes, and unusual traffic patterns for signs of attempted exploitation or service disruption.
While CISA has not publicly linked CVE-2026-88779 to ransomware activities, the KEV entry currently states that the use of ransomware in connection with this vulnerability is unknown.
However, NetScaler appliances remain attractive targets because they often provide remote access, application delivery, and authentication services at the enterprise network edge.
If organizations cannot patch or implement mitigations, CISA advises them to follow applicable cloud-service guidelines or discontinue use of the affected product.
Teams should prioritize externally exposed appliances, preserve relevant forensic evidence, and ensure that remediation is successfully applied across production, disaster recovery, and management environments.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.