Skip to content
Threat Feed
critical threat exploited updated

Active Exploitation of Citrix NetScaler Buffer Vulnerability (CVE-2026-88779)

CISA has added CVE-2026-88779, a memory buffer vulnerability in Citrix NetScaler, to the Known Exploited Vulnerabilities (KEV) catalog due to confirmed in-the-wild exploitation.

CVE search metadata

CVE search record: CVE-2026-88779. Severity: high. CVSS: 7.5. EPSS: 0.28%. KEV: no. Product: NetScaler (< 14.1-73.41), NetScaler ADC (< 14.1-73.41), NetScaler Gateway (< 14.1-73.41). Brief: Active Exploitation of Citrix NetScaler Buffer Vulnerability (CVE-2026-88779). Brief link: https://feed.craftedsignal.io/briefs/2026-10-citrix-netscaler-kev/

What's new

CISA has officially added CVE-2026-88779, a vulnerability categorized as an Improper Restriction of Operations within the Bounds of a Memory Buffer in Citrix NetScaler, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition is based on validated evidence of active exploitation by malicious cyber actors. Vulnerabilities of this class frequently lead to unauthorized remote code execution or system instability by corrupting memory within the application process space. The inclusion in the KEV Catalog triggers requirements under Binding Operational Directive (BOD) 26-04 for federal agencies to prioritize remediation on internet-facing assets. Organizations utilizing Citrix NetScaler must assess their exposure and apply available vendor patches as a priority, given the confirmed active threat environment.

Impact

Successful exploitation of CVE-2026-88779 allows attackers to manipulate memory buffers within Citrix NetScaler, potentially resulting in unauthorized access, service disruption, or remote code execution. Given the nature of Citrix NetScaler as an edge appliance, compromised systems provide attackers with a significant foothold into enterprise networks, enabling lateral movement and further data exfiltration.

Recommendation

  • Prioritize the immediate patching of all internet-facing Citrix NetScaler instances against CVE-2026-88779 as required by BOD 26-04.
  • Audit perimeter logs for anomalous traffic patterns directed at NetScaler appliances, specifically looking for abnormally large payloads or malformed requests that could trigger buffer memory issues.
  • Following remediation, perform a forensic review of logs to determine if the system was compromised prior to the patch application, as mandated by the risk-based vulnerability management requirements outlined in BOD 26-04.

Immediate actions

Patch NetScaler to 14.1-73.41 or later

IT Operations 24h

Threat Hunt

Inspect logs for large, malformed HTTP payloads targeting NetScaler management or gateway interfaces

high high confidence hunt now

Data: Web server access logs, Appliance internal logs

Mitigations

Update NetScaler to 14.1-73.41 or later

immediate IT Operations

CVE-2026-88779