Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns
CISA added CVE-2026-88779 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on October 4, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.
Treat this as an emergency.
