NetScaler ADC exploited in the wild (CVE-2026-88779)
CVE-2026-88779
CVE-2026-88779: NetScaler ADC and Gateway under active exploitation (CVSS 8.7). Update to 14.1-73.41 or 13.1-64.28 immediately to close the attack path.
Actively exploited in the wild - CVE-2026-88779 is a high-severity vulnerability in NetScaler ADC (before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, before 13.1-37.282) and NetScaler Gateway (before 14.1-73.41, before 13.1-64.28) that a remote, unauthenticated attacker can trigger over the network with no user interaction. CISA has added it to the Known Exploited Vulnerabilities catalog, so patched builds should be deployed now rather than scheduled.
Overview
CVE-2026-88779 affects NetScaler ADC and NetScaler Gateway, the application delivery and remote access appliances that many organizations expose directly to the internet to publish web applications and terminate VPN sessions. The vulnerable code paths are reachable over the network, require no credentials, and need no action from a victim, which is the combination that makes edge appliances attractive to mass scanning and rapid exploitation.
NetScaler Gateway is typically deployed as the entry point for remote workers, while NetScaler ADC fronts production web and API traffic. Anything that compromises either role sits in a privileged position: inside the perimeter, adjacent to authentication flows, and in line with session traffic that is normally encrypted end to end.
Impact
Successful exploitation can compromise the confidentiality and integrity of the appliance and, by extension, the services behind it. Because the attack needs no credentials, any internet-reachable management or gateway interface is a candidate target. Organizations should assume that an exposed, unpatched appliance has already been probed, and treat unexplained configuration changes, new local accounts, or unexpected outbound traffic as indicators of compromise.
The CISA KEV listing confirms real-world abuse, so this is not a theoretical exposure. Reports of related intrusions and follow-on breaches are tracked at breach reports, with ongoing coverage at security news.
Remediation and Mitigation
- Upgrade NetScaler ADC to 14.1-73.41 or later, or 13.1-64.28 or later. FIPS deployments need 14.1-73.41 FIPS or later, and the 13.1 FIPS branch requires 13.1-37.282 or later.
- Upgrade NetScaler Gateway to 14.1-73.41 or later, or 13.1-64.28 or later.
- If immediate patching is not possible, restrict management and gateway interfaces to trusted networks and disable public exposure until the upgrade completes.
- Rotate credentials and certificates stored on any appliance that was internet-facing and unpatched, and review authentication logs for anomalous sessions.
- Monitor vendor guidance for updated builds, since edge appliance advisories frequently expand their affected version lists after initial publication.
Security Insight
NetScaler has become a recurring target for edge exploitation, and CVE-2026-88779 follows the pattern set by the CitrixBleed era: an internet-facing appliance, no authentication required, and exploitation that begins before most defenders finish reading the advisory. The EPSS score for this CVE remains very low at roughly 0.3 percent, which is a reminder that probabilistic scoring models lag behind KEV listings when a small number of actors are conducting targeted abuse rather than mass campaigns. For defenders, the lesson is to treat edge appliances as tier-zero assets whose patch cadence should be measured in hours, not maintenance windows.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument P...
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory....
A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. This manipulation of the argument GO causes stack-based buffer overflow. The at...
A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. T...