
Citrix Fixes NetScaler Zero-Day Exploited in Targeted DoS Attacks
Citrix released fixes for CVE-2026-88779, a high-severity NetScaler ADC and Gateway zero-day exploited in targeted attacks to cause denial-of-service.
Citrix has rolled out security updates for a high-severity zero-day vulnerability in its NetScaler ADC and NetScaler Gateway products that attackers have already exploited in targeted campaigns. The flaw, tracked as CVE-2026-88779, carries a CVSS severity score of 8.7 out of 10 and can be abused to knock SAML-based single sign-on deployments offline through a denial-of-service condition. NetScaler ADC is an application delivery controller that manages network traffic to web applications, while NetScaler Gateway provides secure remote access to corporate resources. Both are common in enterprise networks, and the zero-day status means that attackers were exploiting the issue before Citrix had a fix available.
The vulnerability is a memory overflow that Citrix said can lead to denial-of-service "under specific deployment conditions." For an attacker to trigger the flaw, the NetScaler ADC or Gateway must be configured as either a SAML service provider (SP) or a SAML identity provider (IdP). SAML, short for Security Assertion Markup Language, is a widely used standard that lets users sign in once and then access multiple applications without logging in again. Administrators can check whether their NetScaler device meets the precondition by reviewing the configuration for entries that include either "add authentication samlAction" (for a service provider) or "add authentication samlIdPProfile" (for an identity provider). Citrix stressed that only customer-managed deployments running affected supported versions are vulnerable, and only when those SAML settings are present.
The company has addressed the issue in several release families. Users should update to NetScaler ADC and NetScaler Gateway version 14.1-73.41 or later, or version 13.1-64.28 and later releases of the 13.1 branch. For the FIPS-compliant variants, the fixed releases are NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later. Citrix's Cloud Software Group credited security firms Bishop Fox and watchTowr for reporting the vulnerability. In a post on X, watchTowr said its researchers were able to reproduce the flaw within hours of detecting activity on NetScaler honeypots, which are decoy systems set up to lure and observe attackers.
Citrix confirmed that it has observed targeted attacks against unmitigated NetScaler deployments that can cause denial-of-service. If the memory overflow condition is triggered repeatedly, the service may remain unavailable. The company said its analysis indicates the issue affects service availability only, and it has not identified any impact on the integrity of customer data. The patches arrive after Citrix said it was tracking a newly observed problem related to SAML authentication in customer-managed NetScaler deployments, particularly those that combine SAML authentication with Gateway or AAA functionality. AAA stands for authentication, authorization, and accounting, a set of services that control user access to network resources. This development also follows earlier reports of active exploitation of CVE-2026-88771 and CVE-2026-88772, which were used to plant web shells and tunneling tools on compromised systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, which means federal agencies must apply the patches by October 7, 2026. The KEV catalog lists vulnerabilities that are known to be actively exploited, and federal agencies are required to remediate them promptly. For any organisation running NetScaler ADC or Gateway, especially with SAML configured for single sign-on, updating to a fixed version should be treated as urgent because a denial-of-service condition can take employee logins and customer portals offline. The fact that attackers are actively targeting this flaw, combined with previous web shell activity on related CVEs, makes this a priority for security teams.
For website owners and IT teams that rely on remote access or single sign-on, this incident is a reminder that perimeter devices like NetScaler are high-value targets. Keeping such devices patched and reviewing configuration for unnecessary SAML exposure are immediate steps. Organisations that need help staying on top of these updates or assessing their exposure can turn to security-first infrastructure and consulting services such as AEU-I, which supports businesses in managing and securing their IT environments.
How to Protect Yourself
- If your company uses Citrix NetScaler for remote access or single sign-on, ask your IT department to check the version and apply the update right away.
- Find out whether your NetScaler is set up for SAML, because that is the condition attackers need to cause the outage; your IT team can look for the samlAction or samlIdPProfile settings.
- Until the patch is applied, restrict who can reach the NetScaler management and login pages, for example by allowing only trusted office networks.
- Watch for unusual login failures or slowdowns on your remote access or single sign-on pages, and report them to your IT or security team.
- Subscribe to Citrix security bulletins or the CISA KEV list so you learn about urgent patches like this one quickly.
Vulnerabilities & Fixes
- CVE-2026-88771 Previously reported as actively exploited to plant web shells and tunneling tools on compromised systems; no separate fix is detailed in this article. View the fix & details →
- CVE-2026-88772 Previously reported as actively exploited to plant web shells and tunneling tools on compromised systems; no separate fix is detailed in this article. View the fix & details →
- CVE-2026-88779 High-severity memory overflow in Citrix NetScaler ADC and Gateway exploited in targeted denial-of-service attacks; fixed in versions 14.1-73.41, 13.1-64.28, 14.1-FIPS 14.1-73.41 FIPS, and 13.1-FIPS/13.1-NDcPP 13.1-37.282 or later. View the fix & details →
Terms Explained
- zero-day A security flaw that attackers exploit before the software maker has released a fix.
- denial-of-service An attack that makes a service unavailable by overwhelming it or crashing it.
- SAML A standard way for websites to let users sign in once and then access multiple services without signing in again.
- CVSS A scoring system that rates the severity of a security vulnerability from 0 to 10.
- honeypot A decoy system set up by security researchers to attract and observe attackers.
- web shell A small malicious program placed on a server that lets attackers control it remotely.
- KEV catalog A list of known exploited vulnerabilities maintained by CISA that federal agencies must patch.
- CVE A unique identifier for a publicly known security vulnerability.