Citrix security advisory (AV26-996)

Serial Number: AV26-996
Date: October 5, 2026

As of October 4, 2026, Citrix is affected by a vulnerability in the following products:

  • NetScaler ADC
    • Prior to 13.1-37.282
    • Prior to 13.1-64.28
    • Prior to 14.1-73.41
    • Prior to 14.1-73.41 FIPS
  • NetScaler Gateway
    • Prior to 13.1-64.28
    • Prior to 14.1-73.41

Citrix indicates that CVE-2026-88779 is exploited in the wild.

On October 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to their Known Exploited Vulnerabilities (KEV) Catalog.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: