Citrix has rushed out emergency patches for a critical vulnerability in its NetScaler appliances, which has been exploited in targeted attacks that can cause denial-of-service conditions. The flaw, tracked as CVE-2026-88779, affects NetScaler ADC and NetScaler Gateway devices using SAML authentication with Gateway or AAA functionality.
The vulnerability is a memory buffer issue that allows attackers to crash the service, causing it to become unavailable. Citrix has observed targeted attacks on unmitigated NetScaler deployments, and if left unchecked, can lead to repeated denial-of-service conditions. Fortunately, Citrix’s security advisory notes that no data integrity issues have been reported.
The company has released urgent updates for affected devices, including NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28. For FIPS deployments, customers should upgrade to the latest FIPS version, while those on the 13.1 branch should install a specific patch. Citrix is also providing Global Deny Lists to block access from known malicious IP addresses.
However, organizations that recently upgraded their NetScaler devices to fix two actively exploited vulnerabilities will need to do so again, as these patches did not address this latest issue. To determine if your appliance is vulnerable, check whether SAML authentication is configured – a simple step that can help prevent the vulnerability.
But here’s the worrying part: researchers are investigating whether the flaw can be used for remote code execution. While Citrix describes it as a denial-of-service vulnerability, some NetScaler administrators and cybersecurity researchers have seen activity suggesting that attackers may be able to execute malicious code on affected devices. This is still being researched, but it highlights the importance of patching these vulnerabilities as soon as possible.
Citrix has urged customers to install the newly released security updates at the earliest opportunity. By doing so, they can prevent the vulnerability from being exploited and avoid the potential for denial-of-service conditions or even worse – remote code execution.
For those managing NetScaler deployments, it’s essential to take a closer look at their SAML authentication configurations and ensure that all necessary patches have been applied. If you’re not sure whether your device is vulnerable, check with Citrix support or seek guidance from a security expert. Remember, the best way to protect yourself against these types of attacks is to stay up-to-date on the latest patches and updates – and act quickly when new vulnerabilities are discovered.
Source: Bleeping Computer — 2026-10-04