CVE-2026-88779
Citrix NetScaler ADC / Gateway · Load balancers and access gateways (ADC)
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Score from the vendor or CISA, relayed by the NVD. Collected Oct 5, 2026.
- Exploited sinceKEV catalogThe official list, kept by the US cybersecurity agency (CISA), of vulnerabilities that attackers are observed exploiting. A vulnerability only enters it with evidence.
- October 4, 2026
- RansomwareRansomwareAccording to CISA, ransomware groups (which encrypt data for ransom) use this vulnerability.
- None known
- CISA deadlineCISA deadlineThe remediation deadline set for US federal agencies. It does not apply elsewhere, but it is a good sense of urgency.
- 3 days
- CERT-FR alertCERT-FR alertCERT-FR, the incident response center of France’s ANSSI, issues an alert when a vulnerability is exploited at scale or targets France. “Active”: the alert is not closed.
- None
At a glance
CISA asks you to hunt for signs of compromise: patching is not enough if the device has already been breached.
Affected product: Citrix NetScaler ADC / Gateway (category Load balancers and access gateways (ADC), indicative classification). Name in CISA’s catalog: Citrix NetScaler.
What should I do?
Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices.
CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached.
Deadline set by CISA for US federal agencies: 3 days (due October 7, 2026). It only binds those agencies, but it is a useful measure of urgency.
- Citrix security advisories page (general page, not the advisory for this vulnerability)
- The vendor’s specific advisory is listed in the NVD references: CVE-2026-88779 on the NVD website.
Original text of the required action (CISA)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA's "Forensics Triage Requirements" (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Timeline
- Vulnerability published Publication date (NVD)
- Exploitation confirmed Added to CISA’s KEV catalog
- CISA deadline Remediation deadline set for US federal agencies
The facts, with their sources
Each value with its source and collection date. Open for details.
- Exploitation confirmed
- Yes, on October 4, 2026 Date added to the catalog of exploited vulnerabilities. Exploitation itself may have started earlier. Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- Ransomware
- No known use to date That does not guarantee it is not being used: the information is not public. Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- Hunt for compromise
- Requested by CISA Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- CISA required action
- Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices. Rewritten by this site from CISA’s original text. Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- CISA deadline
- October 7, 2026, 3 days Set for US federal agencies: a measure of urgency, not an obligation elsewhere. Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- Vulnerability published
- October 4, 2026 Source: National Vulnerability Database (NVD), collected October 5, 2026 at 06:40 UTC
- Product according to CISA
- Citrix NetScaler Filed by this site under “Load balancers and access gateways (ADC)” (indicative classification). Source: KEV catalog, collected October 5, 2026 at 06:35 UTC
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Technical detail of the score: attack vector, complexity, impact. Source: National Vulnerability Database (NVD), collected October 5, 2026 at 06:40 UTC
Description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Official description from the NVD, collected Oct 5, 2026. CVE® description © The MITRE Corporation.
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Summary from CISA (KEV catalog).
CERT-FR advisories
No advisory among the latest CERT-FR publications this site follows. That does not mean there are none.
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
Sources for this page
- CISA KEV catalog: exploitation, date added, required action, deadline, ransomware.
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- CERT-FR: advisories and alerts (in French).
- Brand and category: indicative classification by this site (method).