Citrix NetScaler CVE-2026-88779 Under Active Exploitation

Summary
Citrix says attackers are targeting unpatched NetScaler ADC and Gateway deployments affected by CVE-2026-88779, a high-severity memory overflow that can cause denial of service. CISA has added it to the KEV Catalog.
Key points
- Citrix disclosed CVE-2026-88779 on October 4, 2026, with a CVSS score of 8.7.
- The memory overflow affects customer-managed NetScaler ADC and Gateway deployments configured as a SAML Service Provider or Identity Provider.
- Successful exploitation can cause denial of service, potentially disrupting authentication and remote access.
- Citrix reports targeted attacks against unpatched deployments; CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.
- Apply the latest Citrix security updates, prioritizing internet-facing and business-critical systems.
- Citrix-managed cloud and Adaptive Authentication services are not affected, according to the article.
Article Details
- Vulnerability Types
- Memory overflow
- Severity
- High (CVSS 8.7)
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- available
CVE
Vendors
Products
NetScaler ADCa high-severity (CVSS score of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service ProviderNetScaler Gatewayscore of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service Provider (SP) or SAML Identity Provider