Citrix NetScaler Targeted Via New Zero Day
Citrix NetScaler zero-day CVE-2026-88779 is under targeted attack and was added to CISA's KEV catalog.
Citrix warned of targeted attacks against NetScaler ADC and NetScaler Gateway using CVE-2026-88779, a CVSS 8.7 memory-buffer flaw that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Builds before 14.1-73.41 and 13.1-64.28 need updates; Citrix also published Global Deny List signatures and said customer data integrity was not affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on October 4 and told federal agencies to apply mitigations by October 7. The report also notes earlier NetScaler zero-days, including KEV-listed CVE-2026-8452.
- CVE-2026-88779 is a CVSS 8.7 memory flaw that can cause denial of service.
- Affected versions are 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28.
- Exposure requires the appliance to be configured as a SAML SP or IdP.
- CISA added it to KEV and ordered federal mitigations by October 7.
- Citrix said data integrity was unaffected and released deny-list signatures.
Vulnerabilities mentionedAll →
- CVE-2026-84528.81%Memory Buffer Overflow in Citrix NetScaler ADC/Gateway Exploited in the Wildpublished · Citrix NetScaler ADC KEV PoC
Full article393 words · extracted from infosecurity-magazine.com · click to collapse
Citrix has warned of “targeted attacks” against its NetScaler ADC and NetScaler Gateway products via a new zero day vulnerability, which could lead to denial of service (DoS) for customers.
The high-severity vulnerability, CVE-2026-88779, is a memory buffer issue which can affect service availability if certain pre-conditions are met. It carries a CVSS rating of 8.7.
In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.
The pre-conditions are met if their configuration contains entries matching either:
- Appliance is configured as a SAML SP add authentication samlAction, or
- Appliance is configured as a SAML IdP add authentication samlIdPProfile
Impacted customers should install updated versions of ADC and Gateway as soon as possible.
Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix. These can be used via the NetScaler Global Deny List feature.
Citrix said the integrity of customer data had not been impacted because of the flaw.
The software company will continue to monitor vulnerability activity and provide updates as needed.
The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.
The agency warned that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”
The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.
Citrix in the Spotlight Following Raft of Vulnerability Disclosures
The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway. This included two critical CVEs under active exploitation.
Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.
Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.
“This is likely due to renewed scrutiny by researchers on the product, including those looking to reproduce the work of whoever found it first, and attackers doing the same,” he noted.
Image credit:Casimiro PT / Shutterstock.com