Government Advisory

CISA Warns of Actively Exploited Citrix NetScaler Flaw: Check Your Systems Now

CISA · 4 Oct 2026
Key Takeaway If your business uses Citrix NetScaler, confirm whether CVE-2026-88779 affects you, apply the vendor's fix as a priority, and check for signs of compromise from before the patch.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw, tracked as CVE-2026-88779, is a memory buffer error (improper restriction of operations within the bounds of a memory buffer). CISA says it has evidence the vulnerability is being actively exploited, and notes that this type of weakness is a frequent attack vector for malicious cyber actors.

CISA's Binding Operational Directive 26-04 requires US federal civilian agencies to prioritise rapid fixes for KEV-listed vulnerabilities on publicly exposed assets that give an attacker total control once exploited. It also sets expectations for checking whether attackers got in before a patch was applied. The directive applies only to those agencies, but CISA encourages all organisations to adopt risk-based vulnerability management and to prioritise remediation of KEV Catalog entries.

The summary does not include details on affected versions or fixes, so businesses running Citrix NetScaler should consult Citrix's own guidance for that information.

Summarised by CISO AI from CISA, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.