DKDKCISSPSearch
Vulnerabilities

Citrix NetScaler Targeted Via New Zero Day

The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.

DKCISSP News DeskInfosecurity Magazine5 Oct 2026, 7:00 pm
Citrix NetScaler Targeted Via New Zero Day
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.

In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.

The pre-conditions are met if their configuration contains entries matching either: Impacted customers should install updated versions of ADC and Gateway as soon as possible.

Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix.

The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.

The agency warned that The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.

Citrix said the integrity of customer data had not been impacted because of the flaw.

Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.

These can be used via the NetScaler Global Deny List feature.

The software company will continue to monitor vulnerability activity and provide updates as needed.

Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.

The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway.

What happened

The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.

In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.

The pre-conditions are met if their configuration contains entries matching either: Impacted customers should install updated versions of ADC and Gateway as soon as possible.

What changed

Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix.

The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.

The agency warned that The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.

Who is affected

Citrix said the integrity of customer data had not been impacted because of the flaw.

Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.

Why it matters

These can be used via the NetScaler Global Deny List feature.

Technical details

The software company will continue to monitor vulnerability activity and provide updates as needed.

Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.

Response

The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway.

Attribution

Infosecurity Magazine: The high-severity vulnerability, CVE-2026-88779 , is a memory buffer issue which can affect service availability if certain pre-conditions are met.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsThe Hacker News · 7 Oct 2026, 5:19 pmAtlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer · 6 Oct 2026, 11:04 pmRed Hat’s Lightwell Project Remediates 400 Open-Source VulnerabilitiesInfosecurity Magazine · 6 Oct 2026, 6:31 pmDell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net SecurityHelp Net Security · 6 Oct 2026, 4:14 pm