CISA added CVE-2026-88779 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on October 4, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Why it matters
CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.
CISA added CVE-2026-104286 (Fortinet FortiMail) to its Known Exploited Vulnerabilities catalog on October 1, 2026, which means there is reliable evidence of exploitation in the wild. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or…
Why it matters
CISA lists this as exploited in the wild. Unpatched FortiGate / FortiOS and FortiMail systems are exposed to active attacks now.
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
Why it matters
There are signs this may already be exploited, which usually shortens the time available to patch.
Patch
Apply the vendor's security update for the affected products.