CISA adds actively exploited Citrix NetScaler flaw to KEV catalog
CISA added CVE-2026-88779, an improper restriction of operations within a memory buffer in Citrix NetScaler, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The agency urges organizations to prioritize remediation; its binding directive applies to federal civilian agencies, while CISA encourages other organizations to use risk-based vulnerability management.
Why it matters For organizations running NetScaler, the listing gives vulnerability teams evidence of exploitation to support remediation prioritization, rather than relying only on the flaw's technical classification.
US Certs Alerts ↗