thehackernews.com 5 Oct 2026, 06:40 UTC

Citrix NetScaler Zero Day Exploited in Targeted Attacks, CISA Warns

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CITRIX has released security updates for a high-severity flaw in NetScaler ADC and Citrix NetScaler Gateway that has been observed being exploited in targeted zero-day campaigns. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7/10.0 and is described as a memory overflow issue that can lead to denial-of-service under certain deployment conditions. The issue affects customer-managed NetScaler deployments that are configured in specific ways with prerequisites met.

Exploitation requires NetScaler ADC or NetScaler Gateway to be configured as either a SAML service provider (SP) or a SAML identity provider (IdP). Organisations can verify their deployment against preconditions by checking for configuration entries such as authentication samlAction (SAML SP) or authentication samlIdPProfile (SAML IdP).

Citrix has provided patched releases: NetScaler ADC and NetScaler Gateway 14.1-73.41 and later; 13.1-64.28 and later in the 13.1 line; 14.1-FIPS 14.1-73.41 FIPS and later in the 14.1-FIPS line; and 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later in their respective FIPS/NDcPP builds. Citrix’s Cloud Software Group credited Bishop Fox and watchTowr for disclosure, with watchTowr stating it could reproduce the flaw within hours of honeypot activity.

CISA has listed CVE-2026-88779 in the Known Exploited Vulnerabilities catalog, setting a deadline for federal agencies to apply patches by 7 October 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline