Citrix issues emergency patch for exploited NetScaler SAML flaw CVE-2026-88779
Citrix has released emergency firmware updates for NetScaler ADC and Gateway appliances to fix CVE-2026-88779, a memory buffer vulnerability in SAML authentication with a CVSS score of 8.7. The company confirmed the bug has already been exploited in targeted attacks against unpatched devices, causing denial-of-service outages, and said it has found no evidence of customer data being compromised. Fixed versions include 14.1-73.41 and 13.1-64.28, with separate builds for FIPS and NDcPP customers.
GoKawiil's interpretation of the reporting above, not reported fact.
Researchers are still examining whether the flaw could be escalated beyond denial-of-service into remote code execution, which would raise the stakes considerably for affected organizations. Administrators who already patched two other recently exploited NetScaler vulnerabilities now face yet another mandatory upgrade cycle, suggesting NetScaler appliances remain a persistent target for attackers. Citrix's provision of IP deny lists as a stopgap indicates the company expects some organizations to delay patching despite active exploitation.
- CVE-2026-88779 is a CVSS 8.7 memory buffer flaw in NetScaler's SAML authentication affecting Gateway and AAA configurations.
- Citrix confirms active zero-day exploitation causing denial-of-service, with no observed impact on data integrity so far.
- Fixed builds 14.1-73.41 and 13.1-64.28 (plus FIPS/NDcPP variants) are available, and Citrix urges immediate upgrades even for recently patched devices.
Source: bleepingcomputer.com, 2026-10-04
Published there as: “Citrix patches NetScaler SAML zero-day exploited in attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.