Citrix issues emergency patch for exploited NetScaler SAML flaw CVE-2026-88779
Citrix has released emergency firmware updates for NetScaler ADC and Gateway appliances to fix CVE-2026-88779, a memory buffer vulnerability in SAML authentication with a CVSS score of 8.7. The company confirmed the bug has already been exploited in targeted attacks against unpatched devices, causing denial-of-service outages, and said it has found no evidence of customer data being compromised. Fixed versions include 14.1-73.41 and 13.1-64.28, with separate builds for FIPS and NDcPP customers.