CITRIX has released security updates for a high-severity flaw in NetScaler ADC and Citrix NetScaler Gateway that has been observed being exploited in targeted zero-day campaigns. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7/10.0 and is described as a memory overflow issue that can lead to denial-of-service under certain deployment conditions. The issue affects customer-managed NetScaler deployments that are configured in specific ways with prerequisites met.
Exploitation requires NetScaler ADC or NetScaler Gateway to be configured as either a SAML service provider (SP) or a SAML identity provider (IdP). Organisations can verify their deployment against preconditions by checking for configuration entries such as authentication samlAction (SAML SP) or authentication samlIdPProfile (SAML IdP).
Citrix has provided patched releases: NetScaler ADC and NetScaler Gateway 14.1-73.41 and later; 13.1-64.28 and later in the 13.1 line; 14.1-FIPS 14.1-73.41 FIPS and later in the 14.1-FIPS line; and 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later in their respective FIPS/NDcPP builds. Citrix’s Cloud Software Group credited Bishop Fox and watchTowr for disclosure, with watchTowr stating it could reproduce the flaw within hours of honeypot activity.
CISA has listed CVE-2026-88779 in the Known Exploited Vulnerabilities catalog, setting a deadline for federal agencies to apply patches by 7 October 2026.