Skip to content
Brief Security & Trust ·

CISA adds Citrix NetScaler memory flaw to its list of exploited bugs

The US agency says it has evidence that attackers are already using the flaw, tracked as CVE-2026-88779.

In brief
  • CISA added CVE-2026-88779, a Citrix NetScaler memory buffer flaw, to its Known Exploited Vulnerabilities list. It cites evidence of active exploitation.
  • US federal agencies must follow a risk-based directive, BOD 26-04. CISA urges all organisations to do the same.

CISA, the US cyber agency, said on 4 October 2026 that it added one flaw to its Known Exploited Vulnerabilities (KEV) Catalog. The catalog lists bugs that attackers are known to be using. CISA said it based the addition on evidence of active exploitation. The entry is CVE-2026-88779, a Citrix NetScaler flaw. CISA describes it as improper restriction of operations within the bounds of a memory buffer. CISA said this kind of flaw is a frequent route for attackers and carries significant risk for the federal enterprise.

CISA's notice does not say who is exploiting the flaw, how many systems are affected, or who the targets are. It gives no severity score and no patch details, and it names no affected NetScaler versions. It also sets no fix deadline for this entry. The notice does describe a separate rule, Binding Operational Directive 26-04, for federal civilian agencies. That rule tells them to fix high-risk KEV flaws first, on internet-facing systems where an attacker would gain full control. It also sets expectations for checking whether attackers got in before the patch.

CISA said the directive applies only to federal agencies, but it urges all organisations to take a risk-based approach and to prioritise KEV fixes. Teams that run Citrix NetScaler can check the CVE against their own versions and look up Citrix's fix guidance. Anyone who tracks the KEV list can treat this entry as a sign of real attacks, not only a theoretical risk.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: CISA.