← Blog · · df00tech

CISA KEV: Citrix NetScaler ADC/Gateway Memory-Buffer Flaw (CVE-2026-88779) Actively Exploited

breaking kev Citrix CVE-2026-88779

What Happened

CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog as of October 4, 2026. The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway), and is classified as an improper restriction of operations within the bounds of a memory buffer. Citrix describes the impact as a denial of service. No CVSS score has been published yet, and known ransomware campaign use is listed as unknown.

Why It Matters

NetScaler ADC and Gateway sit at the network edge as load balancers and remote-access gateways, making them high-value targets — prior NetScaler vulnerabilities have been chained for initial access and persistence in large-scale campaigns. A memory-safety bug leading to denial of service in this position can disrupt VPN/remote-access availability and, depending on exploitation specifics not yet detailed by Citrix, may carry broader risk if further analysis reveals additional impact beyond DoS. Its KEV listing confirms CISA has evidence of active exploitation, meaning this is not theoretical.

What Defenders Should Do Now

  • Identify all internet-facing and internal NetScaler ADC/Gateway appliances and check the version against Citrix's advisory (CTX697174) for patched builds.
  • Apply Citrix's official patch or mitigation guidance as soon as it is validated in your environment — KEV inclusion typically carries a federal remediation deadline, and should be treated with similar urgency elsewhere.
  • Monitor NetScaler logs and uptime/health metrics for unexpected crashes, restarts, or service interruptions that could indicate exploitation attempts targeting this memory-handling flaw.
  • Review network-level logging (load balancer/WAF logs, NetScaler audit logs) for anomalous or malformed traffic patterns preceding any outages.
  • If NetScaler is used for remote access, confirm failover/HA configurations are in place in case exploitation causes service disruption.

Developing Intel

Details are still emerging — Citrix has not published a CVSS score, and the exact exploitation technique and scope beyond denial of service are not yet fully disclosed. We will update as more information becomes available. See Citrix's advisory for the latest guidance: CTX697174.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.