Unauthenticated denial of service in NetScaler ADC and Gateway
CISA: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVSS 4.0
8.7high
EPSS
<1%p47
Published
()
KEV added
AI analysis
CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade NetScaler ADC to 14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, or 13.1-37.282 or later, and NetScaler Gateway to 14.1-73.41 or 13.1-64.28 or later, matching the correct non-FIPS or FIPS train. Until those builds are in place, restrict ADC and Gateway services to trusted networks and monitor for unexpected restarts or loss of availability.
Affected
Citrix NetScaler ADC
before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282
Citrix NetScaler Gateway
before 14.1-73.41 and before 13.1-64.28
Estimated exposure
largetens of thousands of internet-exposed appliances (larger if internal-only deployments are included) — Estimate from the large enterprise installed base of NetScaler ADC and Gateway and historical public internet-scan reporting of on the order of tens of thousands of internet-facing Citrix NetScaler/Gateway appliances; the count still on…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
CISA Known Exploited Vulnerability
Affected
Citrix NetScaler
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Citrix NetScaler zero-day CVE-2026-88779 is exploited in the wild against patched appliances, causing DoS with possible RCE; CISA added it to KEV.
Citrix confirmed CVE-2026-88779, a memory overflow affecting NetScaler ADC and Gateway configured as SAML SP or IdP, is being exploited in targeted attacks causing denial of service, with indications it may also enable remote code execution. Admin logs showed authentication requests with shell commands hidden in the username field fetching a script that plants web shells, persists across reboots, and uploads appliance configurations and backups; Kevin Beaumont observed exploitation attempts against patched honeypots, one downloading a malware binary. CISA added the CVE to its KEV catalog on October 4 with an October 7 federal deadline, the sixth exploited NetScaler vulnerability added in 2026. The bug follows actively exploited zero-days CVE-2026-88771 and CVE-2026-88772 (PitScaler), which had forced some customers to disconnect appliances.
CISA added actively exploited Citrix NetScaler CVE-2026-88779 to KEV after attacks crash ADC and Gateway appliances.
CISA added CVE-2026-88779, a memory-overflow flaw in Citrix NetScaler ADC and Gateway, to the Known Exploited Vulnerabilities catalog. Citrix said targeted attacks on unpatched appliances can cause repeated denial of service and leave services unavailable, with no identified impact on data integrity. The issue affects on-premises deployments that use SAML with Gateway or AAA, including 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, plus listed FIPS builds. Honeypots and customer reports describe crashes, webshell installation attempts, and a downloaded malware binary; US civilian agencies must remediate by October 7, 2026.
Citrix NetScaler and Fortinet FortiMail zero-days are under active attack, alongside ransomware arrests and new threat activity.
Citrix said CVE-2026-88779 (CVSS 8.7), a memory overflow in NetScaler ADC and NetScaler Gateway, is exploited in targeted attacks when the appliance is a SAML service provider or identity provider and can cause denial of service. CISA warned of active exploitation of FortiMail flaw CVE-2026-104286 (CVSS 9.8), which lets unauthenticated attackers write arbitrary files through crafted HTTP or HTTPS requests. The recap also reports arrests tied to ShinyHunters and KillSec, a Spectre v2 variant that leaked Linux root password hashes in minutes on Intel CPUs, and Star Blizzard phishing that installs the CosmicPulse backdoor.
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779 after crashes and possible code execution.
Citrix issued emergency NetScaler ADC and Gateway updates for CVE-2026-88779, a CVSS 8.7 memory-buffer flaw in SAML Gateway or AAA configurations that it says was used in targeted attacks causing denial of service. Fixed releases include 14.1-73.41 and 13.1-64.28, with separate FIPS builds, and Citrix also published deny lists for known malicious IP addresses. Administrators reported nsaaad crash loops and authentication usernames carrying shell commands that tried to download a payload from 213.209.159.55; Kevin Beaumont said a patched honeypot ran a downloaded malware binary. CISA added the CVE to the Known Exploited Vulnerabilities catalog and gave federal agencies until October 7 to mitigate it.
Attackers are exploiting unpatched Citrix NetScaler CVE-2026-88779, a SAML memory overflow that causes denial of service.
Citrix confirmed CVE-2026-88779, a memory overflow in customer-managed NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, can cause denial of service. Attackers exploited it before a patch; CISA confirmed active exploitation and ordered federal agencies to patch by Wednesday. watchTowr said a single crafted request can knock an appliance offline and suspects crashes speed exploitation of earlier bug CVE-2026-88771. Citrix published fixes and an indicator-of-compromise script, crediting watchTowr and Bishop Fox.
CISA orders agencies to patch actively exploited Citrix NetScaler flaw CVE-2026-88779, a confirmed denial-of-service bug.
Citrix assigned CVE-2026-88779, scored 8.7, to a newly observed NetScaler ADC and Gateway issue that can crash customer-managed appliances and keep services unavailable if triggered repeatedly. Citrix said it has seen targeted denial-of-service attacks on unmitigated deployments, credited Bishop Fox and watchTowr, and published mitigations ahead of upgrades. CISA ordered US federal agencies to patch by Wednesday and perform forensic triage, while US and Australian authorities warned customers. Separately, CVE-2026-88771 and CVE-2026-88772 from the prior week remain under active global exploitation, with Mandiant citing likely impact in North America and Europe across government, finance, technology, education, and legal services.
Canada's Cyber Centre warns Citrix NetScaler CVE-2026-88779 is exploited and now on the CISA KEV list.
On October 5, 2026, the Canadian Centre for Cyber Security published advisory AV26-996 on CVE-2026-88779 in Citrix NetScaler ADC and NetScaler Gateway. Affected ADC releases are those before 13.1-37.282, 13.1-64.28, and 14.1-73.41, including the FIPS line, and Gateway releases before 13.1-64.28 and 14.1-73.41. Citrix says the vulnerability is exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on October 4, 2026. The Cyber Centre urges administrators to review Citrix guidance and apply updates.
Citrix patched CVE-2026-88779, a high-severity NetScaler memory overflow exploited as a zero-day.
Citrix patched CVE-2026-88779, a high-severity memory-overflow vulnerability in NetScaler. SOCRadar reports the flaw was exploited as a zero-day before fixes were available. The notice says the overflow affects customer deployments; further technical detail in the source is truncated.
Citrix NetScaler zero-day CVE-2026-88779 is under targeted attack and was added to CISA's KEV catalog.
Citrix warned of targeted attacks against NetScaler ADC and NetScaler Gateway using CVE-2026-88779, a CVSS 8.7 memory-buffer flaw that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Builds before 14.1-73.41 and 13.1-64.28 need updates; Citrix also published Global Deny List signatures and said customer data integrity was not affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on October 4 and told federal agencies to apply mitigations by October 7. The report also notes earlier NetScaler zero-days, including KEV-listed CVE-2026-8452.
Citrix patched exploited NetScaler CVE-2026-88779, a SAML memory overflow that can deny service.
Citrix patched CVE-2026-88779, a CVSS 8.7 memory-overflow flaw in customer-managed NetScaler ADC and NetScaler Gateway that can deny service when the appliance is configured as a SAML service provider or identity provider. Citrix said targeted attacks hit unpatched deployments and that repeated triggering can keep the service unavailable, with no identified impact on customer-data integrity. Fixes are in 14.1-73.41, 13.1-64.28, and corresponding 14.1-FIPS and 13.1-FIPS/NDcPP releases; Bishop Fox and watchTowr were credited. CISA added the CVE to the KEV catalog and required federal agencies to patch by October 7, 2026. The report also notes earlier exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools.
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779, which can deny service on ADC and Gateway appliances.
Citrix issued emergency updates for CVE-2026-88779, a NetScaler SAML memory-overflow zero-day that attackers are actively exploiting against customer-managed ADC and Gateway appliances. The flaw, CVSS v4.0 8.7 and CWE-119, is reachable over the network without credentials or user interaction when the appliance is a SAML service provider or identity provider, and Citrix says confirmed impact is denial of service rather than data integrity loss. Affected builds include 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, and listed FIPS and NDcPP releases; fixed builds are 14.1-73.41, 13.1-64.28, and corresponding FIPS updates. Bishop Fox and watchTowr were credited. Separate reports of shell commands and a honeypot malware binary raise code-execution concerns but are not Citrix’s confirmed description of this CVE.
CISA added actively exploited Citrix NetScaler flaw CVE-2026-88779 to the KEV catalog.
CISA added CVE-2026-88779, a Citrix NetScaler improper restriction of operations within a memory buffer, to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The agency said this vulnerability class is a frequent attack vector and poses significant risk to the federal enterprise. Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of high-risk KEV entries on publicly exposed assets and to check for compromise before patching. CISA encouraged all organizations to prioritize KEV remediation.
CISA added actively exploited Citrix NetScaler CVE-2026-88779, a memory flaw that can deny service, to the KEV catalog.
CISA added Citrix NetScaler CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4, 2026, after confirming active exploitation. The CWE-119 memory-buffer flaw affects NetScaler ADC and NetScaler Gateway and can let an attacker cause a denial of service, disrupting remote access and application delivery. Federal civilian agencies must apply Citrix mitigations by October 7, 2026, under Binding Operational Directive 26-04. CISA says ransomware use is unknown but still requires forensic triage, not patching alone.
CISA added exploited Citrix NetScaler flaw CVE-2026-88779 to KEV, with federal fixes due October 7.
CISA added Citrix NetScaler CVE-2026-88779, a CVSS 8.7 memory-overflow flaw in customer-managed ADC and Gateway, to the Known Exploited Vulnerabilities catalog. Exploitation requires a SAML service-provider or identity-provider configuration and can cause denial of service; Citrix has seen targeted attacks but reports no impact on data integrity. Patches are available in 14.1-73.41, 13.1-64.28, and corresponding FIPS and NDcPP releases, while Citrix-managed cloud services are already updated. Federal agencies must remediate by October 7, 2026.
Citrix says CVE-2026-88779, a NetScaler memory-overflow DoS flaw, is under targeted attack and now in CISA’s KEV catalog.
Citrix disclosed CVE-2026-88779, a memory-overflow flaw in customer-managed NetScaler ADC and Gateway that attackers can repeatedly trigger to cause denial of service. Citrix rated it CVSS 4.0 8.7, said it observed targeted attacks on unmitigated SAML-configured deployments, and reported no identified impact on customer data integrity. Affected releases include 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, plus specified FIPS and NDcPP builds, so customers who applied last week’s fixes may need to upgrade again. CISA added the vulnerability to the KEV catalog with an October 7 remediation deadline for US federal agencies.
CISA added actively exploited Citrix NetScaler CVE-2026-88779, an unauthenticated denial-of-service flaw, to the KEV catalog.
CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026, citing active exploitation. The high-severity Citrix NetScaler ADC and Gateway flaw (CVSS v4 8.7, CWE-119) lets an unauthenticated remote attacker cause a denial of service. Affected releases include builds before 14.1-73.41 and 13.1-64.28, plus specified FIPS versions. Federal civilian agencies must remediate by October 7, 2026 under BOD 26-04; ransomware use is listed as unknown.
Citrix patched CVE-2026-88779, a third exploited NetScaler zero-day causing denial of service on SAML appliances.
Citrix disclosed CVE-2026-88779, its third actively exploited NetScaler zero-day in under two weeks, a high-severity denial-of-service flaw that affects only appliances with SAML enabled. CISA added it to the Known Exploited Vulnerabilities catalog, and watchTowr said exploitation likely began Friday and needs only a single crafted request. The bug is technically unrelated to the prior pair but can crash devices to speed exploitation of CVE-2026-88771. Researchers rate the impact lower than those earlier flaws, though attempts contain shellcode suggesting possible chaining toward remote code execution. Citrix has released a patch and urged customers to apply it quickly.
Citrix patched CVE-2026-88779, a CVSS 8.7 unauthenticated NetScaler SAML memory overflow enabling persistent remote DoS, reportedly exploited in targeted attacks.
Citrix issued emergency updates for CVE-2026-88779, a CWE-119 memory overflow in NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication as SP or IdP, rated CVSS v4 8.7. The flaw is network-exploitable with low attack complexity, requires no authentication or user interaction, and impacts availability by crashing the appliance or service. Fixes are available in 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 (FIPS/NDcPP) builds, and exploitation has been reported in targeted attacks against unmitigated deployments. Bishop Fox and watchTowr are credited for the discovery.
Citrix patched actively exploited NetScaler memory-overflow CVE-2026-88779, which CISA added to the KEV catalog.
Qualys reports that Citrix issued an emergency update for CVE-2026-88779, an actively exploited memory-overflow flaw in NetScaler ADC and NetScaler Gateway that can cause denial of service. CISA added the bug to the KEV catalog and urged patching before October 7, 2026. It applies when the appliance is a SAML service provider or identity provider, including affected 14.1, 13.1, FIPS, and NDcPP builds and Secure Private Access hybrid deployments. Citrix also fixed actively exploited CVE-2026-88771 and CVE-2026-88772; Qualys QID 388894 detects vulnerable assets.
Cisco Talos CAIRN research reveals malware authors embedding natural-language prompt-injection instructions in binaries to evade AI-assisted analysis, succeeding ~35% of the time.
Cisco Talos discloses new CAIRN research on 'A3: AI-Analysis Evasion,' where malware authors embed natural-language instructions in code—from simple ignore comments to 'template spraying' targeting LLMs—to manipulate AI-assisted analysis, steering verdicts roughly 35% of the time. The MANTLEMAZE family pairs these AI deceptions with abusing vulnerable drivers to disable EDR from kernel space. The newsletter also rounds up the week's headlines: Citrix NetScaler CVE-2026-88779 (memory overflow DoS, more zero-day reports), an 8 million-record breach of Denmark's CPR database via a company's lawful access, Warlock ransomware hitting four Spanish/Portuguese victims, and a US Senate healthcare cybersecurity bill after the 190-million-record Change Healthcare breach.