High 8.7 Actively Exploited

NetScaler ADC exploited in the wild (CVE-2026-88779)

CVE-2026-88779

By Yazoul AI · automated

CVE-2026-88779: NetScaler ADC and Gateway under active exploitation (CVSS 8.7). Update to 14.1-73.41 or 13.1-64.28 immediately to close the attack path.

Actively exploited in the wild - CVE-2026-88779 is a high-severity vulnerability in NetScaler ADC (before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, before 13.1-37.282) and NetScaler Gateway (before 14.1-73.41, before 13.1-64.28) that a remote, unauthenticated attacker can trigger over the network with no user interaction. CISA has added it to the Known Exploited Vulnerabilities catalog, so patched builds should be deployed now rather than scheduled.

Overview

CVE-2026-88779 affects NetScaler ADC and NetScaler Gateway, the application delivery and remote access appliances that many organizations expose directly to the internet to publish web applications and terminate VPN sessions. The vulnerable code paths are reachable over the network, require no credentials, and need no action from a victim, which is the combination that makes edge appliances attractive to mass scanning and rapid exploitation.

NetScaler Gateway is typically deployed as the entry point for remote workers, while NetScaler ADC fronts production web and API traffic. Anything that compromises either role sits in a privileged position: inside the perimeter, adjacent to authentication flows, and in line with session traffic that is normally encrypted end to end.

Impact

Successful exploitation can compromise the confidentiality and integrity of the appliance and, by extension, the services behind it. Because the attack needs no credentials, any internet-reachable management or gateway interface is a candidate target. Organizations should assume that an exposed, unpatched appliance has already been probed, and treat unexplained configuration changes, new local accounts, or unexpected outbound traffic as indicators of compromise.

The CISA KEV listing confirms real-world abuse, so this is not a theoretical exposure. Reports of related intrusions and follow-on breaches are tracked at breach reports, with ongoing coverage at security news.

Remediation and Mitigation

  • Upgrade NetScaler ADC to 14.1-73.41 or later, or 13.1-64.28 or later. FIPS deployments need 14.1-73.41 FIPS or later, and the 13.1 FIPS branch requires 13.1-37.282 or later.
  • Upgrade NetScaler Gateway to 14.1-73.41 or later, or 13.1-64.28 or later.
  • If immediate patching is not possible, restrict management and gateway interfaces to trusted networks and disable public exposure until the upgrade completes.
  • Rotate credentials and certificates stored on any appliance that was internet-facing and unpatched, and review authentication logs for anomalous sessions.
  • Monitor vendor guidance for updated builds, since edge appliance advisories frequently expand their affected version lists after initial publication.

Security Insight

NetScaler has become a recurring target for edge exploitation, and CVE-2026-88779 follows the pattern set by the CitrixBleed era: an internet-facing appliance, no authentication required, and exploitation that begins before most defenders finish reading the advisory. The EPSS score for this CVE remains very low at roughly 0.3 percent, which is a reminder that probabilistic scoring models lag behind KEV listings when a small number of actors are conducting targeted abuse rather than mass campaigns. For defenders, the lesson is to treat edge appliances as tier-zero assets whose patch cadence should be measured in hours, not maintenance windows.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.