Citrix NetScaler owners who rushed out patches for last month's zero-days have another update to install. On October 4 the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation, and the builds that fix it are newer than the ones Citrix shipped for September's flaws.
The new bug affects NetScaler ADC and NetScaler Gateway, the remote-access and load-balancing appliances that sit on the edge of many corporate and government networks. CISA lists it as an improper restriction of operations within the bounds of a memory buffer (CWE-119), a memory-handling flaw, and its catalog entry says it could allow for a denial of service, meaning an attacker could knock the appliance offline.
A remote, unauthenticated crash bug
Citrix, acting as the CVE numbering authority, scores the flaw 8.7 (High) under CVSS 4.0. The published vector says it can be reached over the network, with low attack complexity, no privileges and no user interaction, and that the impact falls on availability alone, with no confidentiality or integrity impact recorded. CISA's own triage data for the CVE marks exploitation as active and the attack as automatable, with partial technical impact.
Neither CISA nor the public CVE record describes how the flaw is triggered or who is exploiting it, and the KEV entry lists known ransomware use as unknown. Citrix's security bulletin CTX697174 carries the vendor's detail.
For defenders the timing matters. NetScaler gateways have been under sustained attack since late September, when CISA flagged the first batch of NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772), and researchers have since documented new exploit variants and web shells left behind on compromised devices. Even a crash-only bug on an internet-facing gateway can take remote access down for an entire organization.
September's patched builds are still exposed
According to the CVE record published on October 4, CVE-2026-88779 is fixed in the following releases:
- NetScaler ADC and Gateway 14.1: 14.1-73.41 (and 14.1-73.41 FIPS for ADC)
- NetScaler ADC and Gateway 13.1: 13.1-64.28
- NetScaler ADC 13.1: 13.1-37.282
The builds Citrix released for the September zero-days were 14.1-73.37, 13.1-64.23 and 13.1-37.279. All three sit below the new fixed versions, so an appliance that was updated last month and left alone since is still listed as affected.
Update to 14.1-73.41 or 13.1-64.28 by October 7
CISA has given Federal Civilian Executive Branch agencies until October 7, 2026 to apply Citrix's mitigations under Binding Operational Directive 26-04, or to stop using the product if mitigations are unavailable. The KEV entry also marks the CVE for forensic triage, so agencies are expected to check whether the device was compromised before the fix went on, not just to patch it. Private organizations are not bound by the directive, but CISA urges everyone to prioritize KEV-listed flaws.
Administrators should confirm the running build on every ADC and Gateway instance, move to the fixed release for their branch, and follow the vendor bulletin for anything it adds. Given how heavily these appliances have been targeted over the past two weeks, it is worth treating a gateway that crashed or restarted unexpectedly in recent days as an event to investigate rather than a glitch to reboot past.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.