Citrix NetScaler Flaw Under Active Attack: Unpatched Appliances Risk Losing Remote Access
On 4 October 2026, Citrix disclosed a high-severity vulnerability (CVE-2026-88779, CVSS score 8.7) affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw is a memory overflow that affects appliances configured as either a SAML Service Provider (SP) or a SAML Identity Provider (IdP). If exploited, it can cause a denial of service, which could disrupt authentication services and remote access.
The issue is not just theoretical. Citrix has observed targeted attacks against unpatched NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw affects customer-managed NetScaler ADC and Gateway appliances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication services are not affected, because the required updates have already been applied to those platforms.
Sophos Counter Threat Unit researchers recommend that organisations identify affected systems and apply the latest Citrix security updates as soon as possible. Internet-facing and business-critical deployments should be prioritised. SophosLabs says it continues to monitor for related activity and will deliver detections and protections as they become available.