Back Digital.Nhs.Uk CC-4862 - Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-88779)
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) under specific deployment conditions
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) under specific deployment conditions
The following platforms are known to be affected:
14.1 prior to 14.1-73.41
13.1 prior to 13.1-64.28
FIPS prior to 14.1-73.41 FIPS
FIPS and NDcPP prior to 13.1-37.282
14.1 prior to 14.1-73.41
13.1 prior to 13.1-64.28
The following platforms are also known to be affected:
Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.
Active Exploitation of CVE-2026-88779
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses continued exploitation as highly likely.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance , including patching edge devices as soon as possible if a critical vulnerability is identified.
Citrix published a security advisory for a vulnerability affecting Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
CVE-2026-88779 - 'Memory overflow' vulnerability - CVSS v4 score: 8.7.
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) when NetScaler ADC or NetScaler Gateway is be configured as a SAML SP or SAML IdP.
Affected organisations should review Citrix advisory CTX697174 and apply the relevant updates as soon as possible.
Definitive source of threat updates
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Last edited: 5 October 2026 2:30 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
