HomeSecurityCitrix NetScaler: CVE-2026-88779 vulnerability is actively exploited

Citrix NetScaler: CVE-2026-88779 vulnerability is actively exploited

Citrix says it has observed targeted attacks against unpatched NetScaler appliances that exploit the CVE-2026-88779. The flaw can cause the gateway to fail, but the company describes it as a denial of service and not a confirmed remote code execution vulnerability.

CVE-2026-88779 vulnerability in NetScaler gateway

The vulnerability affects NetScaler ADC and NetScaler Gateway when configured for specific use of SAML authentication. Citrix rates the severity as high, with a CVSS 4.0 score of 8.7, and urges administrators to check both the version and configuration of their devices.

See also: Citrix NetScaler RCE: Two new zero-day vulnerabilities in active exploitation

What we know about the CVE-2026-88779 vulnerability

According to the Citrix security bulletin, the vulnerability, CVE-2026-88779, concerns a memory overflow that could lead to a denial of service. The requirement is that the appliance is operating as a SAML service provider or SAML identity provider; not all NetScaler installations are automatically affected.

The company says that repeated triggering of the bug can take the service down. It also notes that it has not yet identified any impact on the integrity of customer data. The bulletin does not confirm remote code execution, so administrators should not confuse this case with different, previous vulnerabilities in NetScaler.

Beazley Security 's incident response team describes attempts to force reboots on NetScaler appliances, which were linked to a separate, older vulnerability. Beazley did not detect command execution on systems that had already been patched for that earlier vulnerability.

NetScaler appliance outage

The distinction is important, as CVE-2026-88779 can cause a denial of service, while CVE-2026-88771 and CVE-2026-88772 involved different bugs and different attack possibilities. The BleepingComputer report also describes attack indications and under-investigated questions about possible code execution; these are not confirmations that CVE-2026-88779 allows code execution.

The National Vulnerability Database (NVD) , notes that it was added to CISA's list of vulnerabilities that have already been exploited in attacks on October 4. The October 7 deadline applies to US federal agencies; for other organizations, the listing highlights the need to immediately check and install the fix.

Which versions fix the CVE-2026-88779 vulnerability?

Citrix has updates available for the supported series. For NetScaler ADC and NetScaler Gateway appliances in the 14.1 series, version 14.1-73.41 or later is required, while for the 13.1 series, version 13.1-64.28 or later is required. For FIPS versions, the corresponding fix is ​​14.1-73.41 FIPS.

For NetScaler ADC FIPS and NDcPP appliances in the 13.1 series, Citrix is ​​defining version 13.1-37.282 or later as fixed. The company clarifies that customers who have installed previous updates for CVE-2026-88771 through CVE-2026-88778 should upgrade again if their appliance meets the requirements for the new vulnerability.

Citrix's bulletin applies to devices that customers manage themselves, as the company says it is updating its own cloud services. In hybrid Secure Private Access deployments that include NetScaler, administrators should also upgrade devices that they manage themselves.

Before upgrading, administrators can check for an entry for add authentication samlAction or add authentication samlIdPProfile . The former corresponds to a SAML service provider role and the latter to an identity provider role. Citrix recommends checking the relevant services and installing the appropriate patch without delay.

See also: Citrix NetScaler: Creation of Superuser accounts and Web Shells via CVE-2026-88771

Temporary protection and control of devices

Where immediate upgrade is not possible, Citrix describes Global Deny List signatures as a temporary measure. The feature has release and configuration requirements, so administrators should follow the company's detailed instructions and not consider the measure a substitute for installing the update.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Citrix NetScaler security upgrade

Organizations managing remote access gateways need to record which devices are using SAML, confirm the software branch and version, and review events for unusual reboots or outages. If there are indications of a breach, they should follow their organization's investigation process.

See also: Technical details for critical vulnerability in Citrix NetScaler

The SecNews technical team recommends not assuming an installation is secure just because it has received previous patches. Assessing SAML configuration and migrating to the versions listed by Citrix are key steps to mitigate the risk from the CVE-2026-88779 vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS