Digital.Nhs.Uk Active Exploitation of Citrix NetScaler Vulnerability CVE-2026-88779
Article Content
- •CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler appliances.
- •Active exploitation is confirmed, with a CVSS score of 8.7 indicating high severity.
- •Emergency patches have been released; organizations must update affected systems immediately.
CISA has flagged a newly disclosed vulnerability in Citrix NetScaler appliances, identified as CVE-2026-88779, which is currently being. This vulnerability, characterized as a memory overflow, can lead to denial-of-service (DoS) under specific configurations. Citrix has released emergency patches for affected versions, including NetScaler ADC and NetScaler Gateway, prior to 14.1-73.41 and 13.1-64.28. Organizations are urged to apply these patches immediately, as the vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog. The NHS England National CSOC assesses continued exploitation as highly likely, emphasizing the attractiveness of internet-facing devices to attackers. The CVSS score for this vulnerability is 8.7, indicating a high severity level.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-88779 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is this vulnerability being actively exploited?
What should organizations do?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical RCE Vulnerability in Rejetto HFS A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) allows unauthenticated remote code execution (RCE) due to a weak pseudo-random number generator (PRNG) used for session keys. Discovered by Anthropic's Mythos AI, the flaw affects HFS versions 3.0.0 to 3.2.0, with a CVSS score of 9.3.…