Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.
The vulnerability specifically impacts appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, which are used for single sign-on authentication. Citrix acknowledged the issue late Friday, October 3, 2026, stating it was investigating a "newly observed issue related to SAML authentication in customer-managed NetScaler deployments."
By Saturday night, October 4, Citrix released a security advisory and patches for NetScaler ADC and NetScaler Gateway, urging customers to install the updates immediately. The company also published a blog post confirming observed targeted attacks on unmitigated NetScaler deployments that could result in denial of service.
On Sunday, October 5, the US Cybersecurity and Infrastructure Security Agency (CISA) verified that CVE-2026-88779 was under active exploitation and mandated federal agencies to patch the vulnerability by Wednesday, October 8.
While CVE-2026-88779 is distinct from eight other CVEs disclosed by Citrix on September 27, some researchers suspect it may be used in conjunction with previous exploits. Specifically, watchTowr researchers believe this new vulnerability could be employed to intentionally crash machines, potentially accelerating the exploitation of CVE-2026-88771, one of the earlier bugs that had been abused for weeks prior to its official disclosure.
According to watchTowr, the vulnerability is remarkably simple to trigger, requiring only a single specially crafted request to take an appliance offline. The disruption of an authentication gateway can prevent legitimate users from accessing services behind it.
WatchTowr successfully reproduced the vulnerability on Friday, October 3. Citrix has credited both watchTowr and Bishop Fox for their assistance in addressing the issue.
Citrix has provided an indicator-of-compromise script for customers to check exposed appliances for signs of compromise, though a clean result does not definitively prove an absence of compromise. Organizations are advised to prioritize patching appliances configured as a Gateway or AAA virtual server with SAML authentication enabled. If an immediate upgrade is not feasible, Citrix has also offered an interim mitigation.






