A vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-88779, was reportedly exploited in the wild at least two days before its public disclosure on October 4, 2026. The flaw, described as an improper restriction of operations within memory buffer bounds, could lead to a denial-of-service condition.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026, with a federal fix deadline of October 7, 2026. CISA advises organizations to apply vendor-provided mitigations, adhering to its BOD 26-04 guidance for prioritizing security updates and forensics triage requirements. For cloud services, CISA recommends following applicable BOD 26-04 guidance or discontinuing product use if mitigations are unavailable.
While CISA listed the vulnerability as exploited on October 4, 2026, the European Union Agency for Cybersecurity (ENISA) and the Computer Incident Response Center Luxembourg (CIRCL) had already listed it as exploited on October 2, 2026. This indicates that active exploitation was observed prior to the official CVE publication date.
The vulnerability was reserved as a CVE on September 10, 2026, and publicly published on October 4, 2026. Its CVSS score indicates a high severity, and its EPSS (Exploit Prediction Scoring System) percentile is 18.2%, suggesting a moderate likelihood of exploitation.
Public reports referencing the vulnerability began appearing as early as September 27, 2026, across various platforms. Citrix has acknowledged the issue and provided support articles, CTX697174, and a tech zone blog post for understanding and addressing the vulnerability.






