A NetScaler vulnerability added to CISA's Known Exploited Vulnerabilities catalog on October 4 carries a federal due date of October 7. Its entry calls for mitigation under vendor instructions and compliance with CISA's forensic-triage guidance.
The entry is CVE-2026-88779. CISA describes a memory-buffer restriction flaw affecting NetScaler ADC and NetScaler Gateway that could cause denial of service.
Three catalog entries in eight calendar days
The catalog also lists CVE-2026-88771 and CVE-2026-88772, both added September 27 with September 30 due dates. CISA describes the former as allowing an unauthenticated attacker to execute arbitrary commands and the latter as potentially permitting remote code execution or denial of service.
Filtering CISA's feed for Citrix or NetScaler entries added from September 27 through October 4 produces three entries. The eight-day interval counts both endpoints; it is this desk's calculation. The date added is a catalog date, not necessarily the date a flaw was discovered or first exploited.
Mitigation and triage are separate duties
The newest entry marks forensicTriage: Yes. Its required-action field points to vendor mitigation instructions, BOD 26-04 and CISA's forensic-triage requirements. Triage is not presented as an optional substitute for fixing or mitigating the vulnerability.
The directive's mandatory requirements apply to Federal Civilian Executive Branch agencies. The catalog is also a prioritization input for other organizations, but its federal due date is not a universal legal deadline for every operator.
What this record cannot supply
The catalog does not establish which appliance builds are affected or which exact update an administrator should install. It links to vendor guidance; those deployment-specific instructions must be checked separately.
CISA records known ransomware-campaign use as Unknown. That field should not be converted into either a claim of ransomware use or a claim that none has occurred. The catalog establishes CISA's exploited-vulnerability listing and required federal response.
