CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks
CISA added actively exploited Citrix NetScaler CVE-2026-88779, a memory flaw that can deny service, to the KEV catalog.
CISA added Citrix NetScaler CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4, 2026, after confirming active exploitation. The CWE-119 memory-buffer flaw affects NetScaler ADC and NetScaler Gateway and can let an attacker cause a denial of service, disrupting remote access and application delivery. Federal civilian agencies must apply Citrix mitigations by October 7, 2026, under Binding Operational Directive 26-04. CISA says ransomware use is unknown but still requires forensic triage, not patching alone.
- CISA added CVE-2026-88779 to the KEV catalog on October 4, 2026.
- CWE-119 memory-buffer flaw can deny service on NetScaler ADC and Gateway.
- Federal agencies must remediate by October 7, 2026, under BOD 26-04.
- Ransomware use is unknown, but CISA requires forensic triage of affected assets.
- Internet-facing NetScaler appliances should be patched or taken out of use.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article454 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler vulnerability, tracked as CVE-2026-88779, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer issue, classified under CWE-119.
The vulnerability could allow an attacker to trigger a denial-of-service condition on affected NetScaler appliances, potentially disrupting access to business applications, remote services, and network resources delivered through the devices.
CISA added the vulnerability to the KEV catalog on October 4, 2026, and set an October 7, 2026, remediation deadline for federal civilian executive branch agencies.
The agency requires organizations to apply vendor-provided mitigations under Binding Operational Directive 26-04, which prioritizes security updates based on risk.
Citrix NetScaler Vulnerability Exploited
The short remediation window highlights the urgency of the issue. NetScaler ADC and Gateway products are commonly exposed to the internet. They are frequently used to provide secure remote access, application delivery, load balancing, and virtual private network services.
A service-disruption vulnerability affecting these systems can create significant operational impact, especially for organizations that depend on them for employee or customer connectivity.
CISA’s listing confirms active exploitation but does not state whether the vulnerability has been used in ransomware operations. The agency marked ransomware use as unknown.
However, it also requires forensic triage for affected assets, indicating that organizations should not treat patching as the only required response. Security teams should first identify all internet-facing and internally deployed NetScaler ADC and Gateway appliances.
Administrators should verify the installed software version, review Citrix security guidance, and deploy the available fix or mitigation as soon as possible. If no mitigation is available, CISA advises organizations to discontinue use of the affected product where feasible.
Forensic teams should examine device logs and surrounding network telemetry for unusual traffic, repeated crashes, unexpected service restarts, configuration changes, suspicious administrator activity, and indicators of post-exploitation access. Organizations should also review authentication records for remote-access services hosted through NetScaler appliances.
The vulnerability reinforces a recurring security concern around edge infrastructure. Because appliances such as NetScaler sit between external users and internal systems, they are attractive targets for attackers seeking an initial foothold or a way to interrupt critical services.
Fast asset discovery, exposure reduction, patch validation, and incident triage are essential when an edge-device flaw enters CISA’s actively exploited catalog.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.