Skip to main content
Emerging ThreatsMalware & Ransomware

Citrix Warns of Targeted Attacks Via New Zero-Day Flaw

Server room with networking gear, one rack having an empty slot.

CVE-2026-88779, a high-severity memory buffer flaw with a CVSS rating of 8.7, was added to the U.S. Cybersecurity and Infrastructure Agency’s Known Exploited Vulnerabilities catalog on October 4 after Citrix warned of “targeted attacks” against its NetScaler ADC and NetScaler Gateway products.

CVE-2026-88779: impact and characterization

Citrix describes CVE-2026-88779 as a memory buffer issue that can affect service availability — specifically resulting in denial of service (DoS) — when certain pre-conditions are met. The company said the vulnerability could disrupt services for impacted customers but that “the integrity of customer data had not been impacted because of the flaw.” Citrix published a security update on October 4 and urged affected customers to act.

Exact product versions and configuration pre-conditions

Citrix identified the affected software builds precisely. The vulnerability affects NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28. The pre-conditions Citrix called out are configuration entries matching either of two specific cases:

  • “Appliance is configured as a SAML SP add authentication samlAction,” or
  • “Appliance is configured as a SAML IdP add authentication samlIdPProfile.”

Customers whose appliance configurations include those entries are the ones Citrix said are at risk of the DoS condition tied to CVE-2026-88779.

Citrix mitigations: updates, signatures, and operational guidance

Citrix advised impacted customers to install updated versions of ADC and Gateway “as soon as possible.” As an interim measure while organizations plan upgrades, Citrix released signatures that can be deployed via the NetScaler Global Deny List feature to reduce exposure. The company said it will continue to monitor vulnerability activity and provide updates as needed.

CISA response and a federal compliance deadline

The U.S. Cybersecurity and Infrastructure Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4 and warned that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” The agency instructed federal agents to apply Citrix’s mitigations by Wednesday, October 7.

What this means for security teams, federal agencies, and affected enterprises

  • Security teams and technologists: Review NetScaler ADC/Gateway configurations for the two SAML-related entries Citrix specified and prioritize installation of the fixed builds (14.1-73.41 or later for 14.1; 13.1-64.28 or later for 13.1). Deploy Citrix’s signatures via the NetScaler Global Deny List while scheduling upgrades.
  • Federal agencies: CISA’s KEV listing and the October 7 mitigation deadline create an immediate compliance window; agencies were instructed to apply Citrix’s mitigations by that date.
  • Affected enterprises and procurement leaders: Confirm whether deployed appliances match the enumerated vulnerable versions and SAML profiles, and factor expedited patching and signature deployment into maintenance plans.

The Citrix advisory arrives on the heels of an earlier bulletin: on September 27 the company confirmed eight zero day flaws in ADC and Gateway, including two critical CVEs reported to be under active exploitation. Another memory overflow flaw affecting those products, CVE-2026-8452, was added to CISA’s KEV list on August 26, indicating a string of recent disclosures for the same product families. Dan Andrew, head of security at Intruder, reflected on that pattern: “This is likely due to renewed scrutiny by researchers on the product, including those looking to reproduce the work of whoever found it first, and attackers doing the same.”

Citrix has provided fixes and temporary signatures; CISA has set a federal mitigation timeline. Citrix said customer data integrity was not affected and that it will keep monitoring the situation and updating guidance. The immediate dossier of facts — the CVE identifier, affected versions, the narrow SAML pre-conditions, Citrix signatures via Global Deny List, and the CISA KEV listing with an October 7 federal deadline — establishes the steps organizations named in the advisory must now take.

Original story: https://www.infosecurity-magazine.com/news/citrix-netscaler-zero-day/