CISA Warns of Citrix Vulnerability Active Exploitation in Attacks (CVE-2026-88779)
Citrix patched actively exploited NetScaler memory-overflow CVE-2026-88779, which CISA added to the KEV catalog.
Qualys reports that Citrix issued an emergency update for CVE-2026-88779, an actively exploited memory-overflow flaw in NetScaler ADC and NetScaler Gateway that can cause denial of service. CISA added the bug to the KEV catalog and urged patching before October 7, 2026. It applies when the appliance is a SAML service provider or identity provider, including affected 14.1, 13.1, FIPS, and NDcPP builds and Secure Private Access hybrid deployments. Citrix also fixed actively exploited CVE-2026-88771 and CVE-2026-88772; Qualys QID 388894 detects vulnerable assets.
- CVE-2026-88779 is a memory overflow that can crash vulnerable NetScaler appliances.
- Exploitation requires the appliance configured as a SAML SP or IdP.
- Fixed builds include 14.1-73.41 and 13.1-64.28 and later releases.
- Citrix also patched actively exploited CVE-2026-88771 and CVE-2026-88772.
- Qualys QID 388894 detects vulnerable NetScaler assets.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article291 words · extracted from threatprotect.qualys.com · click to collapse
Citrix released an emergency update to address an actively exploited vulnerability impacting Citrix NetScaler ADC and Citrix NetScaler Gateway. Tracked as CVE-2026-88779, successful exploitation of this memory overflow vulnerability may allow an attacker to achieve a denial-of-service condition.
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before October 7, 2026.
Citrix has also addressed two actively exploited vulnerabilities (CVE-2026-88771 & CVE-2026-88772) impacting NetScaler deployment.
Pre-conditions
NetScaler ADC or NetScaler Gateway must be configured as a
- SAML SP
OR
- SAML IdP
Customers can determine whether their NetScaler deployment meets the precondition by inspecting their NetScaler configuration for entries matching either of the following:
- Appliance is configured as an SAML SP
add authentication samlAction
OR
- Appliance is configured as an SAML IdP
add authentication samlIdPProfile
Affected versions
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.41
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.28
- Citrix NetScaler ADC FIPS BEFORE 14.1-73.41 FIPS
- Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.282
Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Users need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerability.
Mitigation
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Please refer to the Citrix Security Bulletin (CTX697174) for more information.
Qualys Detection
Qualys customers can scan their devices with QID 388894 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174