CVE-2026-88779
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
- CVSS
- 8.7
- EPSS
- —
- CISA KEV
- Added 2026-10-04, due 2026-10-07
- Exploitation
- active
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Actively exploitedCritical 100BleepingComputerAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Actively exploitedCritical 90CISA advisories & alertsAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability This type of vulnerability is a frequent attack…
What we observed
- kev addedcisa-kev