Citrix NetScaler Targeted Via New Zero Day
The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.

The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.
In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.
The pre-conditions are met if their configuration contains entries matching either: Impacted customers should install updated versions of ADC and Gateway as soon as possible.
Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix.
The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.
The agency warned that The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.
Citrix said the integrity of customer data had not been impacted because of the flaw.
Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.
These can be used via the NetScaler Global Deny List feature.
The software company will continue to monitor vulnerability activity and provide updates as needed.
Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.
The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway.
What happened
The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.
In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.
The pre-conditions are met if their configuration contains entries matching either: Impacted customers should install updated versions of ADC and Gateway as soon as possible.
What changed
Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix.
The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.
The agency warned that The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.
Who is affected
Citrix said the integrity of customer data had not been impacted because of the flaw.
Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.
Why it matters
These can be used via the NetScaler Global Deny List feature.
Technical details
The software company will continue to monitor vulnerability activity and provide updates as needed.
Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.
Response
The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway.
Attribution
Infosecurity Magazine: The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.