Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush
Summary
Citrix has issued a warning for a new high-severity vulnerability (CVE-2026-88779) in its NetScaler ADC and NetScaler Gateway products, which allows for denial-of-service attacks. This comes shortly after the company advised customers to patch other actively exploited zero-day flaws in the same products. The new vulnerability requires specific preconditions for exploitation and has been observed in targeted attacks.
IFF Assessment
This article highlights a new actively exploited vulnerability in critical infrastructure products, posing a direct threat to organizations.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching Citrix NetScaler appliances immediately, given the active exploitation of this and previous vulnerabilities. Organizations need to be vigilant about the security of edge appliances, as they remain a prime target for attackers seeking initial access.