Product

NetScaler ADC / Gateway

Made by Citrix (Cloud Software Group). 6 of its vulnerabilities are known to have been exploited.

Coverage

Severity: ElevatedAction: Be aware

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

CISA added CVE-2026-88779 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on October 4, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: HighAction: ReviewExploitation: Suspected

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88772 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on September 27, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771 , CVE-2026-88772 , CVE-2026-88773 , CVE-2026-88774 , CVE-2026-88775 , CVE-2026-88776 , CVE-2026-88777 , and CVE-2026-88778 . CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog . Both are critical, zero-day…

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Coverage

    US, Australia warn of latest Citrix vulnerability after NetScaler advisory

    Basis: Reporting by The Record by Recorded Future News

  2. Severity raisedUpdateKEV

    UPDATE: severity raised to critical: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  3. AdvisoryKEV

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  4. Added to CISA KEVCVE-2026-88779

    CVE-2026-88779 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

  5. Coverage

    Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    Basis: Reporting by Dark Reading

  6. Coverage

    US, UK warn of exploited Citrix NetScaler zero-day bugs

    Basis: Reporting by The Record by Recorded Future News

  7. Added to CISA KEVCVE-2026-88772

    CVE-2026-88772 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

  8. Added to CISA KEVCVE-2026-88771

    CVE-2026-88771 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Input Validation Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited

Citrix NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Added Oct 4, 2026Fed. due Oct 7, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Improper Input Validation Vulnerability

Added Sep 27, 2026Fed. due Sep 30, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Added Sep 27, 2026Fed. due Sep 30, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Added Sep 9, 2026Fed. due Sep 12, 2026

Citrix NetScaler

Citrix NetScaler Out-of-Bounds Read Vulnerability

Added Mar 30, 2026Fed. due Apr 2, 2026

Citrix NetScaler

Citrix NetScaler Memory Overflow Vulnerability

Added Aug 26, 2025Fed. due Aug 28, 2025