Skip to content
Active Exploitation of Citrix NetScaler Vulnerability CVE-2026-88779

Active Exploitation of Citrix NetScaler Vulnerability CVE-2026-88779

First seen 5 Oct 2026, 18:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 18:09 UTC
  • •CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler appliances.
  • •Active exploitation is confirmed, with a CVSS score of 8.7 indicating high severity.
  • •Emergency patches have been released; organizations must update affected systems immediately.

CISA has flagged a newly disclosed vulnerability in Citrix NetScaler appliances, identified as CVE-2026-88779, which is currently being. This vulnerability, characterized as a memory overflow, can lead to denial-of-service (DoS) under specific configurations. Citrix has released emergency patches for affected versions, including NetScaler ADC and NetScaler Gateway, prior to 14.1-73.41 and 13.1-64.28. Organizations are urged to apply these patches immediately, as the vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog. The NHS England National CSOC assesses continued exploitation as highly likely, emphasizing the attractiveness of internet-facing devices to attackers. The CVSS score for this vulnerability is 8.7, indicating a high severity level.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
CVE-2026-88779 published
Citrix disclosed a memory overflow vulnerability affecting multiple NetScaler versions.
Digital.Nhs.Uk
2026-10-04
CVE-2026-88779 added to CISA KEV
CISA included the vulnerability in its Known Exploited Vulnerabilities catalog due to active exploitation.
Digital.Nhs.Uk
2026-10-05
Emergency patches released
Citrix published emergency updates for affected NetScaler ADC and Gateway versions.
Digital.Nhs.Uk

More articles in this cluster (3)

Following this threat?

Track CVE-2026-88779 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Affected versions include NetScaler ADC prior to 14.1-73.41 and 13.1-64.28.
Is this vulnerability being actively exploited?
Yes, active exploitation has been confirmed by CISA and other sources.
What should organizations do?
Organizations must apply the emergency patches released by Citrix immediately to mitigate the risk.