Citrix has rolled out crucial security patches to address a high-severity vulnerability discovered in its NetScaler ADC and NetScaler Gateway products. These updates arrive in response to active zero-day exploits targeting these systems.
Details of the Vulnerability
The flaw, identified as CVE-2026-88779, has been assigned a CVSS score of 8.7, indicating its severity. This vulnerability is a memory overflow issue that could lead to denial-of-service conditions under specific configurations.
Citrix has indicated that the vulnerability impacts customer-managed deployments of NetScaler ADC and Gateway, specifically when configured as a SAML service provider (SP) or SAML identity provider (IdP). To determine susceptibility, customers should examine their setups for configurations like ‘add authentication samlAction’ or ‘add authentication samlIdPProfile’.
Patch Availability and Acknowledgments
To mitigate this issue, Citrix has released fixes for several NetScaler versions, including 14.1-73.41 and later, 13.1-64.28 and subsequent 13.1 versions, as well as 14.1-FIPS 14.1-73.41 FIPS and later releases. The company credited Bishop Fox and watchTowr for their role in identifying the vulnerability.
WatchTowr noted on social media that they could replicate the vulnerability shortly after detecting activity on a NetScaler honeypot. Citrix has confirmed targeted attacks on unpatched systems, warning that repeated triggering of the condition could lead to prolonged service unavailability.
Implications and Further Developments
While Citrix has not observed any impact on data integrity, the vulnerability significantly affects service availability. The company continues to monitor related issues, particularly in configurations using SAML authentication with Gateway or AAA functionalities.
This development comes amid reports of other vulnerabilities, CVE-2026-88771 and CVE-2026-88772, being actively exploited, leading to the installation of web shells and tunneling tools on affected systems. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the patches by October 7, 2026.
Citrix’s swift response underscores the importance of regular security updates and monitoring for organizations relying on these critical systems.
