By Abinaya
Publication Date: 2026-10-05 13:44:00
The U.S. Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler vulnerability, tracked as CVE-2026-88779, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer issue, classified under CWE-119.
The vulnerability could allow an attacker to trigger a denial-of-service condition on affected NetScaler appliances, potentially disrupting access to business applications, remote services, and network resources delivered through the devices.
CISA added the vulnerability to the KEV catalog on October 4, 2026, and set an October 7, 2026, remediation deadline for federal civilian executive branch agencies.
The agency requires organizations to apply vendor-provided mitigations under Binding Operational Directive 26-04, which…



