Citrix NetScaler CVE-2026-88779: 3rd Zero-Day Hits KEV

Citrix NetScaler CVE-2026-88779: 3rd Zero-Day Hits KEV

By Sofia Lindström
Publication Date: 2026-10-07 03:56:00

Citrix NetScaler is back in the Known Exploited Vulnerabilities catalog for the second time in ten days. On October 6, 2026, researchers and vulnerability trackers flagged CVE-2026-88779, a memory-overflow flaw in NetScaler ADC and NetScaler Gateway appliances, as actively exploited in targeted attacks, according to Security Affairs and vulnerability-intelligence site ZeroHour.day. The bug carries a CVSS v4 score of 8.7, and it hits the same enterprise edge appliances that Citrix, the Cybersecurity and Infrastructure Security Agency, and a long list of incident responders spent late September scrambling to patch after two other zero-days, CVE-2026-88771 and CVE-2026-88772, were found under active attack.