Citrix NetScaler memory buffer flaw added to CISA KEV (CVE-2026-88779)

At a glance

Severity HIGH
CVSS CVE-2026-88779: 8.7
EPSS (30-day exploit probability) CVE-2026-88779: 0.3%
In CISA KEV (exploited) Yes, due 2026-10-07
Vendor Citrix
CVE IDs CVE-2026-88779

CISA added a memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88779, to its Known Exploited Vulnerabilities (KEV) catalog on 4 October 2026, which means exploitation in the wild has been confirmed. Federal agencies must act by 7 October 2026, and any organisation running affected builds should treat that date as a sensible target too.

This Citrix NetScaler vulnerability carries a CVSS 4.0 score of 8.7 (High). CISA describes the impact as a possible denial of service.

What happened

The flaw is an improper restriction of operations within the bounds of a memory buffer, classed as CWE-119. NVD published the record on 4 October 2026, the same day CISA added it to KEV. Citrix has published a security bulletin (CTX697174) and a blog post explaining the issue and how to address it.

Details of how attackers are exploiting it, who is doing so and how widely have not been disclosed in the sources we reviewed. CISA lists known ransomware campaign use as Unknown.

Am I affected? Check your NetScaler version

The NVD description lists these builds as affected, meaning anything earlier than the version shown:

  • NetScaler ADC before 14.1-73.41
  • NetScaler ADC before 13.1-64.28
  • NetScaler ADC before 14.1-73.41 FIPS
  • NetScaler ADC before 13.1-37.282
  • NetScaler Gateway before 14.1-73.41
  • NetScaler Gateway before 13.1-64.28

NVD has not yet filled in a structured product list, so check the Citrix bulletin for the authoritative scope, including any other releases and whether NetScaler-managed cloud services are covered.

Technical details

  • Attack vector: network, low complexity, no privileges and no user interaction required (from the CVSS vector).
  • Impact: the vector rates availability impact high and confidentiality and integrity impact none, which fits the denial-of-service wording from CISA.
  • KEV status: added 4 October 2026, due date 7 October 2026.
  • EPSS: 0.00276, a low modelled probability of exploitation. This conflicts with the confirmed exploitation, so rely on KEV rather than EPSS here.

Why this matters

Analysis, not new facts. NetScaler appliances usually sit at the network edge and handle remote access or load balancing. A flaw that can be reached over the network without authentication, and that is already exploited, is a priority even if the stated outcome is an outage rather than code execution. A crash of a gateway can cut off remote workers and published applications.

Memory corruption bugs can sometimes be pushed further than first described, but nothing in the sources says that is the case here. CISA’s required action also references forensics triage, which hints that responders should check for signs of compromise, not just patch.

What to do: how to fix CVE-2026-88779

  1. Identify every NetScaler ADC and Gateway instance, including FIPS builds and any internet-facing ones.
  2. Upgrade to 14.1-73.41 or later, 13.1-64.28 or later, or 13.1-37.282 or later for the FIPS line, as applicable to your branch. Confirm the exact fixed builds in Citrix bulletin CTX697174.
  3. Where you cannot upgrade at once, apply the mitigations in the Citrix guidance. CISA says to discontinue use of the product if mitigations are unavailable.
  4. Prioritise internet-exposed appliances and aim to finish within hours, not days, given KEV listing.
  5. Review CISA’s forensics triage requirements and check appliance and upstream logs for unexpected restarts, crashes or core dumps around and before 4 October.
  6. Tell your remote-access and application owners about possible short maintenance windows.

Detection and hunting ideas

No indicators of compromise have been published in the sources. Reasonable starting points are repeated unexpected NetScaler process crashes or reboots, unusual spikes of inbound requests to gateway virtual servers, and any new core files on the appliance.

Open questions

Several points remain undisclosed in the material available: the exploitation method, the number of compromised or targeted appliances, the identity of any attacker, and whether a workaround exists short of upgrading. We will update this post if Citrix or CISA add detail.

Sources