Skip to content
Rota Nacional

Cyber ·

CISA adds CVE-2026-88779 in Citrix NetScaler to the KEV catalog

CISA added CVE-2026-88779, an improper restriction of operations within the bounds of a memory buffer flaw in Citrix NetScaler, to the KEV catalog based on evidence of active exploitation. BOD 26-04 directs federal civilian agencies to prioritize fixing high-risk KEV vulnerabilities.

On October 4, 2026, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an improper restriction of operations within the bounds of a memory buffer in Citrix NetScaler, and the listing was based on evidence of active exploitation. According to the alert, this kind of vulnerability is a frequent attack vector and poses significant risks to the federal sector.

The item also cites Binding Operational Directive (BOD) 26-04, which sets vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. It requires those agencies to prioritize rapid remediation of KEV CVEs on publicly exposed assets that would grant full control after exploitation, while deferring lower-risk items. It also sets baseline expectations for checking whether threat actors compromised the system before patching. The directive applies only to FCEB agencies, but CISA encourages all organizations to adopt risk-based vulnerability management.

To be considered for KEV inclusion, a vulnerability needs a CVE ID, evidence of exploitation, and clear mitigation guidance. The text was provided as a machine translation of the CISA feed. To confirm dates, criteria and mitigation steps, consult the original alert published by CISA.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free