On October 4, 2026, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an improper restriction of operations within the bounds of a memory buffer in Citrix NetScaler, and the listing was based on evidence of active exploitation. According to the alert, this kind of vulnerability is a frequent attack vector and poses significant risks to the federal sector.
The item also cites Binding Operational Directive (BOD) 26-04, which sets vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. It requires those agencies to prioritize rapid remediation of KEV CVEs on publicly exposed assets that would grant full control after exploitation, while deferring lower-risk items. It also sets baseline expectations for checking whether threat actors compromised the system before patching. The directive applies only to FCEB agencies, but CISA encourages all organizations to adopt risk-based vulnerability management.
To be considered for KEV inclusion, a vulnerability needs a CVE ID, evidence of exploitation, and clear mitigation guidance. The text was provided as a machine translation of the CISA feed. To confirm dates, criteria and mitigation steps, consult the original alert published by CISA.