ZeroDayAlert

CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

Citrix NetScaler Added to KEV 2026-10-04 Federal due 2026-10-07 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Citrix NetScaler ADC and Citrix NetScaler Gateway products are affected by a memory buffer boundary violation that can cause denial of service. The record does not specify which versions are vulnerable, which deployment modes are at risk, or whether the flaw requires authentication. You should assume both on-premises and cloud-hosted instances may be vulnerable until Citrix publishes version-specific guidance.

How to check whether this touches you

  • Search your asset inventory for NetScaler ADC and NetScaler Gateway instances, including those operated by third parties on your behalf.
  • Establish whether each instance is reachable from the internet or from untrusted networks; denial-of-service flaws are often exploitable remotely.
  • Check Citrix's published advisories and security bulletins for the affected version range and any interim workarounds; version strings alone do not confirm whether a fix has been backported.
  • If you run NetScaler in a cloud service, verify with your provider whether they have applied patches and ask for evidence of their patch timeline.

What to do

  1. Obtain the affected version range and available patch versions from Citrix immediately; do not rely on version numbers in this advisory.
  2. If you cannot patch within the federal remediation window (7 October 2026), apply network controls to restrict access to NetScaler instances from untrusted sources and document your justification.
  3. Enable detailed logging on NetScaler instances to capture connection attempts, errors, and resource exhaustion patterns that might indicate exploitation attempts.
  4. Plan your patch deployment in advance, including test environments and change-control procedures; memory safety flaws often require full service restart.
  5. If your organisation is unable to apply mitigations and no compensating controls are feasible, follow BOD 26-04 guidance on discontinuing use of the product.

If you find you were exposed

Exploitation of denial-of-service flaws often leaves sparse logs, because the goal is to crash or overload the service itself. Review NetScaler logs, system crash dumps, and upstream firewall or load-balancer records for evidence of unusual traffic patterns or repeated connection spikes in the weeks before the advisory date. Retention of at least 30 days of logs is essential; longer retention increases your chance of detecting compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-88779 is being exploited. It cannot tell you whether NetScaler is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →