A critical vulnerability, CVE-2026-88779, affecting Citrix NetScaler ADC and NetScaler Gateway appliances was actively exploited in the wild at least two days before its official publication date of October 4, 2026. This pre-disclosure exploitation meant there was no patch window for affected organizations.
The flaw is described as an improper restriction of operations within the bounds of a memory buffer, which could be leveraged by attackers to cause a denial-of-service condition. Citrix confirmed the active exploitation of this zero-day vulnerability and issued urgent security updates to address it.
The vulnerability was first listed as exploited in the European Union's EUVD catalogue on October 2, 2026. Subsequently, it was added to the U.S. federal CISA Known Exploited Vulnerabilities (KEV) catalog and VulnCheck KEV on October 4, 2026, the same day the CVE was officially published. The CISA KEV listing mandates U.S. federal agencies to apply mitigations by October 7, 2026.
Public exploitation evidence was reported as early as September 27, 2026, with 17 public reports collected from various sources by October 4, 2026. The vulnerability carries a high severity rating, though its CVSS score was not specified. Its Exploit Prediction Scoring System (EPSS) percentile is 18.2%, indicating a moderate likelihood of exploitation.
Organizations utilizing Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are strongly advised to apply the vendor's recommended security updates immediately to mitigate the risk of denial-of-service attacks.






