Skip to main content
Emerging ThreatsMalware & Ransomware

Citrix NetScaler Zero-Day Exploited in Targeted Attacks

Large, empty server room with rows of computer equipment and networking gear.

"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said.

What the flaw is and the preconditions for exploitation

Citrix describes CVE-2026-88779 as a memory overflow vulnerability in customer-managed NetScaler ADC and NetScaler Gateway deployments that, when specific configuration conditions are met, can lead to service disruption. The vulnerability carries a CVSS score of 8.7 out of 10.0. For exploitation to succeed, a NetScaler instance must be configured as either a SAML service provider (SP) or a SAML identity provider (IdP).

Citrix published exact configuration markers customers can use to verify exposure: look for entries matching either "add authentication samlAction" (SAML SP) or "add authentication samlIdPProfile" (SAML IdP). Citrix warned that "if the condition is triggered repeatedly, the service may remain unavailable," and noted that their analysis "indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."

Affected releases and the patched versions

Citrix has issued fixes in specific NetScaler releases. The addressed versions listed by the vendor are:

  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Citrix cautioned that the issue affects customer-managed deployments running affected supported versions when the required preconditions are met; applying the listed updates is the vendor's prescribed mitigation.

Observed exploitation and links to other active attacks

Citrix said it has "observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service." The vendor also noted the flaw is related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.

The release of patches for CVE-2026-88779 comes amid other active exploitation reports: the development follows prior reports that CVE-2026-88771 and CVE-2026-88772 were being actively exploited to deploy web shells and tunneling tools on compromised systems. The vendor framed CVE-2026-88779 as affecting service availability rather than data integrity.

Independent researcher group watchTowr said in a post shared on X that it "has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity." Citrix credited security researchers Bishop Fox and watchTowr for reporting the vulnerability to its Cloud Software Group.

CISA action and the federal deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog. That listing carries a binding operational deadline for federal civilian agencies: CISA requires the patch to be applied by October 7, 2026.

The KEV designation signals that federal agencies must remediate according to the timeline set by CISA. Citrix's advisory and the CISA catalog listing together create a narrow window for remediation in the federal space.

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: Verify whether NetScaler instances are configured as SAML SP or SAML IdP by searching configurations for "add authentication samlAction" and "add authentication samlIdPProfile," and apply the vendor-listed patches where those conditions and affected versions exist.
  • Affected enterprises and procurement leaders: Prioritize patching on customer-managed NetScaler ADC and NetScaler Gateway instances running the affected versions; the vendor explicitly links the vulnerability to SAML deployments using Gateway or AAA functionality.
  • Adversaries and threat actors: Citrix's observation of targeted attacks and watchTowr's rapid reproduction indicate that the flaw is both discoverable in the wild and of operational interest to attackers seeking to disrupt service availability rather than to exfiltrate data.

Citrix has characterized CVE-2026-88779 as an availability-impacting memory overflow that requires particular SAML roles to be configured on customer-managed NetScaler appliances. The company and external researchers have observed exploitation attempts, and CISA's KEV listing imposes an imminent federal remediation deadline of October 7, 2026. For organizations that run NetScaler ADC or NetScaler Gateway in SAML SP or IdP roles, the immediate task is straightforward and time-bound: check configurations for "add authentication samlAction" or "add authentication samlIdPProfile" and deploy the vendor's updates to the versions listed by Citrix.

Original story