A Fresh Citrix Zero-Day Is Already Being Exploited, and Federal Agencies Have Three Days to Fix It

CVE-2026-88779 hit live networks almost immediately after Citrix shipped patches for two earlier flaws, leaving IT teams scrambling again.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: A server rack in a dimly lit data centre
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • CVE-2026-88779, a high-severity memory-buffer flaw in Citrix NetScaler ADC and NetScaler Gateway, was added to CISA's Known Exploited Vulnerabilities catalogue on 2026-10-04, confirming active exploitation in the wild.
  • US federal agencies must patch by 2026-10-07, giving government IT teams a three-day window.
  • The flaw can let attackers crash the affected appliance, knocking out access controls for entire organisations.
  • Affected versions span multiple NetScaler ADC and Gateway release lines; fixed builds are available now.

Citrix NetScaler products sit at the front door of thousands of corporate and government networks. NetScaler ADC (Application Delivery Controller) is the box that routes web traffic into an organisation. NetScaler Gateway is the VPN service, meaning the remote-access tunnel, that staff use to log in from outside the office. When either goes down, people simply cannot get in.

That is exactly what CVE-2026-88779 can do. It's a memory-buffer vulnerability: the software fails to properly control how data is written into a reserved block of memory, so an attacker who sends a crafted packet can trigger a crash. The result is a denial-of-service condition where the box stops responding and the network door slams shut.

How serious is this, and who is affected?

CISA, the US Cybersecurity and Infrastructure Security Agency, had evidence of real attacks by 2026-10-04 and listed the flaw in the catalogue it maintains of vulnerabilities criminals are actively using against real targets. Think of that catalogue as CISA's public alarm bell. Being on it means someone is doing this right now, not just in a lab.

What makes the timing particularly grim, as SecurityWeek first reported, is that this zero-day surfaced just days after Citrix had patched two other actively exploited vulnerabilities in the same product family. We covered those two flaws on 27 September, when watchTowr researchers confirmed attackers were already breaking into unpatched NetScaler boxes and no fix yet existed. Organisations that had just finished that patching cycle are now back at the start of another one.

What should ordinary people and IT teams do?

For most employees, the direct risk is disruption rather than data theft. A crashed Gateway means you can't work remotely until it's restored, and a crashed access-control box can also serve as a distraction alongside a separate break-in attempt elsewhere.

IT and network teams running Citrix NetScaler ADC or Gateway should check their version numbers immediately and update to the fixed builds Citrix has now shipped. US federal teams face a mandatory deadline of 2026-10-07. Everyone else should treat this with the same urgency. Denial-of-service flaws in VPN and load-balancing kit have a long history of being used as a first step to soften a target before a more damaging follow-on attack.

Should you worry?

The real problem here is patching cadence. Three actively exploited Citrix flaws inside a single patch cycle is a pattern worth naming plainly: Citrix appliances are being treated by attackers as reliable soft spots, and defenders' response windows are shrinking each time. If you're running NetScaler in any form, it's time to move these updates to the top of the queue.

© 2026 Threat Vectr