Ravie LakshmananOct 05, 2026Zero-Day / Vulnerability
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.
The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.
“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” Citrix said. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”
For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following –
- SAML SP – add authentication samlAction
- SAML IdP – add authentication samlIdPProfile
The issue has been addressed in the following versions –
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix’s Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. In a post shared on X, watchTowr said it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity.
“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service,” the company acknowledged. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”
The patches come after Citrix said it’s tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it’s related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.
The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

