## Overview
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026. This vulnerability affects Citrix NetScaler ADC and Gateway products. It allows for improper restriction of operations within the bounds of a memory buffer, which could lead to a denial of service.
## Technical Details
The affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and their FIPS counterparts. For NetScaler Gateway, the vulnerable versions are before 14.1-73.41 and 13.1-64.28. The CVSS score for this vulnerability is 8.7, indicating a high severity level. Evidence of exploitation has prompted CISA to act quickly, adding urgency to the need for remediation.
## Impact
If exploited, this vulnerability could allow attackers to disrupt service availability. A denial of service could impact businesses relying on these products for application delivery and secure remote access. Organizations using affected versions are at risk of significant operational disruptions.
## Mitigation
Defenders should immediately update their Citrix NetScaler ADC and Gateway products to the latest versions. Patching is critical to mitigate the risk of exploitation. Regularly monitor Citrix’s security advisories for updates and additional guidance.
CSURFACE Threat Sensor