- Citrix released security updates for CVE-2026-88779, a high-severity memory overflow flaw in NetScaler ADC and Gateway exploited in targeted zero-day attacks.
- The vulnerability (CVSS 8.7) affects customer-managed deployments configured as SAML service providers or identity providers, potentially enabling denial-of-service.
- Patch versions include NetScaler ADC/Gateway 14.1-73.41 and 13.1-64.28; the U.S. CISA added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal fixes by October 7, 2026.
- Researchers from Bishop Fox and watchTowr reported the flaw; watchTowr reproduced it within hours of detecting honeypot activity.
Citrix released security updates for a high-severity memory overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway that threat actors have exploited in targeted zero-day attacks. Tracked as CVE-2026-88779, the flaw carries a CVSS score of 8.7 out of 10.0.
The issue affects customer-managed NetScaler deployments running supported versions when configured either as a SAML service provider (SP) or SAML identity provider (IdP). According to Citrix, “CVE-2026-88779 is a memory overflow vulnerability … that can lead to denial-of-service under specific deployment conditions.”
Consequently, Citrix acknowledged targeted attacks on unmitigated deployments. The company stated, “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.” The patches address the flaw in NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28, along with FIPS variants.
The development follows reports of active exploitation of two other vulnerabilities, CVE-2026-88771 and CVE-2026-88772, used to plant web shells and tunneling tools. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by October 7, 2026.
Citrix credited Bishop Fox and watchTowr for reporting the flaw. In a post on X, watchTowr said it reproduced the security flaw within hours of detecting NetScaler honeypot activity.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
