www.infosecurity-magazine.com 5 Oct 2026, 13:30 UTC

Citrix warns attackers are exploiting a NetScaler zero day

CyberSIXT Evidence Panel

CITRIX has warned of targeted attacks against its NetScaler ADC and NetScaler Gateway via a new high-severity zero-day vulnerability, CVE-2026-88779, a memory buffer issue that can affect service availability under certain pre-conditions. The CVSS score is 8.7.

Citrix’s security update, published on 4 October, calls on customers using NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28 to review their configurations, specifically to examine whether Security Assertion Markup Language (SAML) authentication actions are configured. The pre-conditions required to trigger impact are entries in the appliance configuration matching either: “SAML SP add authentication samlAction” or “SAML IdP add authentication samlIdPProfile”.

Citrix has issued mitigations, including signatures that can be deployed via the NetScaler Global Deny List to reduce exposure while upgrades are planned. Citrix states that the integrity of customer data has not been impacted by the flaw.

The United States Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on 4 October and warned that this class of vulnerability is a frequent attack vector with significant risks to the federal enterprise, directing federal agencies to apply Citrix’s mitigations by 7 October.

The article notes this follows a September update from Citrix confirming eight zero-day flaws in ADC and Gateway, with two under active exploitation, and mentions a related memory overflow flaw, CVE-2026-8452, added to KEV in August.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline