By Tamilselvan
Publication Date: 2026-10-05 10:01:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Citrix NetScaler vulnerability, tracked as CVE-2026-88779, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation.
The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer vulnerability, classified under CWE-119.
CISA Warns of Citrix NetScaler Flaw
Such weaknesses can occur when software does not adequately validate memory operations, potentially allowing an attacker to trigger a denial-of-service condition against vulnerable appliances.
CISA added the vulnerability to the KEV Catalog on October 4, 2026, and set an October 7, 2026 remediation deadline for impacted federal civilian executive branch agencies.
The accelerated timeline underscores the operational risk of…

