Cyber & AI intelligence
Wasteland.
Briefs indexed3010
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-88779 2026-10-04

Citrix NetScaler ADC and Gateway Memory Buffer Flaw Under Active Exploitation (CVE-2026-88779)

"CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. It is a memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can let an attacker cause a denial of service. Federal agencies…"

CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. It is a memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can let an attacker cause a denial of service. Federal agencies must remediate it by October 7, 2026.

What Is It

CVE-2026-88779 is a memory buffer vulnerability (CWE-119) in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). CISA lists it as "Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability." CISA says the flaw could allow a denial of service.

The vendor gave it a CVSS 4.0 base score of 8.7 (HIGH) with this profile:

Why It Matters

CISA's KEV catalog confirms active exploitation. CISA added the CVE on October 4, 2026. CISA's SSVC assessment records exploitation as "active," automatable as "yes," and technical impact as "partial."

NetScaler ADC and Gateway devices often handle remote access and application delivery. An unauthenticated attacker who can reach the device over the network can disrupt it.

CISA has also marked this entry Yes for forensic triage. CISA's required action therefore includes its Forensics Triage Requirements in addition to applying fixes. Whether the flaw has been used in ransomware campaigns is listed as Unknown.

What's Vulnerable

According to the NVD record, these versions are affected:

NetScaler ADC: - 14.1 before 14.1-73.41 - 13.1 before 13.1-64.28 - 14.1 FIPS before 14.1-73.41 FIPS - 13.1-FIPS and 13.1-NDcPP before 13.1-37.282

NetScaler Gateway: - 14.1 before 14.1-73.41 - 13.1 before 13.1-64.28

Patch Status

Citrix has published guidance in security bulletin CTX697174 and in a related Citrix TechZone post. Based on the affected version ranges, the fixed releases are:

CISA required action: Apply mitigations according to vendor instructions. Follow CISA's BOD 26-04 guidance (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow the BOD 26-04 guidance for cloud services, or stop using the product if mitigations are unavailable. Under BOD 26-04, agencies must assess each asset's internet exposure and follow the directive's patching guidelines.

Due date: October 7, 2026.

Sources