Citrix security advisory (AV26-996)
Canada's Cyber Centre warns Citrix NetScaler CVE-2026-88779 is exploited and now on the CISA KEV list.
On October 5, 2026, the Canadian Centre for Cyber Security published advisory AV26-996 on CVE-2026-88779 in Citrix NetScaler ADC and NetScaler Gateway. Affected ADC releases are those before 13.1-37.282, 13.1-64.28, and 14.1-73.41, including the FIPS line, and Gateway releases before 13.1-64.28 and 14.1-73.41. Citrix says the vulnerability is exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on October 4, 2026. The Cyber Centre urges administrators to review Citrix guidance and apply updates.
- CVE-2026-88779 affects NetScaler ADC and NetScaler Gateway.
- Citrix says the flaw is exploited in the wild.
- CISA added the CVE to the KEV catalog on October 4, 2026.
- Builds before the listed 13.1 and 14.1 releases are vulnerable.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article121 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-996
Date: October 5, 2026
As of October 4, 2026, Citrix is affected by a vulnerability in the following products:
- NetScaler ADC
- Prior to 13.1-37.282
- Prior to 13.1-64.28
- Prior to 14.1-73.41
- Prior to 14.1-73.41 FIPS
- NetScaler Gateway
- Prior to 13.1-64.28
- Prior to 14.1-73.41
Citrix indicates that CVE-2026-88779 is exploited in the wild.
On October 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to their Known Exploited Vulnerabilities (KEV) Catalog.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-996