CISA adds another Citrix NetScaler vulnerability to its catalogue of exploited flaws
CISA has added CVE-2026-88779, a memory management flaw in Citrix NetScaler, to its catalogue of exploited vulnerabilities. This comes a week after an alert for two critical zero-days in NetScaler ADC and Gateway.

News summary
On 4 October 2026, CISA added vulnerability CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue, described as an improper restriction of operations within the bounds of a memory buffer in Citrix NetScaler. Its inclusion indicates that there is evidence of active exploitation.
On 27 September, CISA had already warned of eight vulnerabilities in NetScaler ADC and Gateway, two of which were critical zero-days involving remote code execution. On 2 October, it updated that alert with a SIGMA detection rule to help identify suspicious activity.
NetScaler is the remote access gateway for many companies: if compromised, an attacker gains a foothold inside the network. CISA recommends checking for indicators of compromise before applying updates and preserving evidence, as updating can erase useful forensic data.
Spanish companies using NetScaler should treat these patches as a priority and review the Citrix bulletin to identify affected versions.
Source: CISA — 4 October 2026
Frequently Asked Questions
- Is it enough to update NetScaler?
- Patching closes the vulnerability, but it will not remove an attacker who has already gained entry. That is why we recommend checking for indicators of compromise before and after.
- Where can I find the affected versions?
- In the Citrix security advisory for each CVE, which is the official source for affected versions and fixes.
Concepts mentioned in this article: Vulnerability
Remote access gateways are a prime target for attackers. At Seintec, we can review your exposure, apply patches, and hunt for indicators of compromise. Talk to our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.