Skip to the stories
Tuesday, 6 October 2026
Saved

Next edition

0:13

Headlines

Cybercrime and Scams

CISA adds actively exploited Citrix NetScaler zero day to KEV catalog

The Cybersecurity and Infrastructure Security Agency has added a memory overflow vulnerability in Citrix NetScaler appliances to its catalog of actively exploited security flaws.

FTMQ Security, written by our newsroom0 views

Share
Picture: Help Net Security

The Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog on Sunday, Help Net Security and Security Affairs reported. The flaw, identified as CVE-2026-88779, is a memory overflow vulnerability that affects Citrix NetScaler ADC and Gateway appliances. [1][7][10]

Help Net Security and TechNadu report that the zero-day flaw is being actively exploited in targeted attacks. According to Citrix, the vulnerability can lead to a denial of service that leaves services unavailable if triggered repeatedly. As FTMQ Security reported earlier, researchers are investigating whether the security issue can also allow remote code execution. [1][2][10]

NetScaler functions as an application delivery controller that offers load balancing and traffic management features for concurrent user sessions. As FTMQ Security reported earlier, Citrix has released emergency security patches to address the issue in unmitigated deployments. [9][10]

The warning from CISA follows reports from CyberSecurityNews and eSecurity Planet indicating that the vulnerability has been actively targeted in ongoing attacks against unpatched systems. [3][4][5][6]

Share

In short

  • CVE-2026-88779 is a memory overflow flaw in Citrix NetScaler ADC and Gateway.
  • CISA added the zero-day vulnerability to its Known Exploited Vulnerabilities catalog on Sunday.
  • Citrix has observed targeted attacks causing denial of service conditions on unmitigated deployments.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)Help Net Security, 23h ago (the report this story comes from)
  2. [2]CVE-2026-88779: Citrix NetScaler Zero-Day Exploited in Targeted AttacksTechNadu, 1d ago
  3. [3]CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in AttacksCyberSecurityNews, 23h ago
  4. [4]Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 Exploited in AttackseSecurity Planet, 23h ago
  5. [5]CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacksgbhackers.com, 1d ago
  6. [6]CISA Warns of Citrix NetScaler Flaw Actively Exploited in Attackscyberpress.org, 1d ago
  7. [7]U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs, 1d ago

Background

  1. [8]United States Department of Homeland Security on Wikipedia
  2. [9]NetScaler on Grokipedia
  3. [10]Citrix issues patches for NetScaler memory overflow flaw under active attack FTMQ Security, 14h ago

Our newsroom writes these reports with the help of software, from the 10 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Cybercrime and Scams

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.