Citrix NetScaler flaws CVE-2026-88779 and CVE-2026-88771 exploited
Citrix and CISA warn NetScaler CVE-2026-88779 is exploited for denial of service, while related critical flaw CVE-2026-88771 is also under attack.
Citrix issued emergency NetScaler ADC and Gateway updates for CVE-2026-88779, a CVSS 8.7 memory overflow that targeted attacks used to crash customer-managed appliances and cause denial of service. Reported fixed releases are 14.1-73.41 and 13.1-64.28, plus FIPS builds; on October 5, Canada's Cyber Centre said earlier 13.1 and 14.1 builds, including ADC builds before 13.1-37.282, are affected. CISA placed the CVE in the KEV catalog on October 4 and gave US federal agencies until October 7 to mitigate it, with The Record adding a forensic-triage order and warnings from US and Australian authorities. Sources disagree on the vulnerable configuration—SAML as service provider or identity provider versus SAML with Gateway or AAA—and on whether exploitation hit only unmitigated systems or also patched honeypots. Citrix reported no impact on data integrity, while other coverage describes possible code execution, a downloaded malware binary, web shells, or configuration theft. Separately, LevelBlue reports ongoing exploitation of critical pre-authentication flaw CVE-2026-88771, patched September 27, and CVE-2026-88772 remains under active exploitation.
- CVE-2026-88779 is a CVSS 8.7 memory-buffer overflow in customer-managed NetScaler ADC and Gateway; Citrix says targeted attacks cause denial of service, while some outlets say code execution may also be possible.
- Cited fixes are 14.1-73.41 and 13.1-64.28, including FIPS builds. Canada's Cyber Centre advisory AV26-996 says ADC builds before 13.1-37.282, 13.1-64.28, and 14.1-73.41 are affected.
- CISA added CVE-2026-88779 to the KEV catalog on October 4, 2026, with a federal deadline of October 7. The Record says agencies must also perform forensic triage, and that US and Australian authorities warned customers.
- Sources disagree on scope and targets: some limit exposure to SAML service-provider or identity-provider setups, others to SAML with Gateway or AAA; most say unpatched or unmitigated appliances were hit, but SecurityWeek and Kevin Beaumont…
- Citrix said data integrity was unaffected, credited watchTowr and Bishop Fox, and published deny-list signatures and an indicator script. Other reporting describes malware, web shells, or configuration theft.
- Separately, CVE-2026-88771 is a CVSS 9.5 pre-authentication command-injection flaw patched on September 27, 2026, in 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP builds. LevelBlue reported active intrusions.
- CVE-2026-88771 and CVE-2026-88772 remain exploited; SecurityWeek called that pair PitScaler and said CVE-2026-88779 was the sixth exploited NetScaler flaw added to KEV in 2026. Infosecurity also noted KEV-listed CVE-2026-8452.
Coverage timelineoldest first · each row is one article
- · 6d agoCitrix patches NetScaler SAML zero-day exploited in attacks
BleepingComputer· 88
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779 after crashes and possible code execution.
- · 6d agoCitrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
Cyber Security News· 82
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779, which can deny service on ADC and Gateway appliances.
- · 6d ago
Vulnerabilities in this storyAll →
- CVE-2025-65439.211%Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wildpublished · Citrix NetScaler ADC KEV