Citrix NetScaler Zero Day Under Targeted Attack, Putting Business Availability at Risk
Citrix has warned of targeted attacks against its NetScaler ADC and NetScaler Gateway products through a new zero day vulnerability, tracked as CVE-2026-88779. The flaw is a memory buffer issue that can disrupt service availability if certain pre-conditions are met. It carries a high-severity CVSS rating of 8.7. Citrix said the integrity of customer data had not been impacted by the flaw.
In a security update published on October 4, Citrix asked customers running NetScaler ADC and Gateway 14.1 before 14.1-73.41, or 13.1 before 13.1-64.28, to review their configurations to see whether SAML authentication actions are set up, as this is the condition that creates exposure. Affected customers should install updated versions as soon as possible. Citrix has also released signatures that can be deployed through the NetScaler Global Deny List feature to reduce exposure while upgrades are planned.
The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on October 4 and told federal agencies to apply Citrix's mitigations by October 7. This follows a September 27 Citrix bulletin confirming eight zero day flaws in ADC and Gateway, including two critical ones under active exploitation. Another memory overflow flaw, CVE-2026-8452, was added to the CISA list on August 26. Dan Andrew of Intruder noted that vulnerabilities often surface in quick succession in a given product, likely because of renewed scrutiny from researchers and attackers alike.