Citrix issues urgent NetScaler patch as attackers target a new flaw
Citrix says attackers are targeting a NetScaler vulnerability that can cause service outages on affected appliances. The flaw applies to ADC and Gateway systems using SAML authentication with Gateway or AAA functionality; Citrix has released emergency updates and urges customers to install them.
Bottom line — Citrix rates CVE-2026-88779 at 8.7 out of 10, and says eligible NetScaler deployments need the new update.
Go deeper 6
-
Computing reports that exploitation can trigger denial-of-service conditions; researchers are investigating whether it could also enable remote code execution.
-
Citrix says the vulnerability affects systems configured as a SAML service provider or identity provider.
-
The updates include NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28, with separate versions for some FIPS and NDcPP deployments.
-
Administrators reported repeated crashes and crafted authentication usernames containing shell commands, but the logs did not establish that the commands executed.
-
Cybersecurity firm watchTowr Labs said it reproduced the vulnerability while investigating activity involving NetScaler honeypots, without publishing technical details.
-
Intruder security head Dan Andrew said memory corruption can sometimes provide a route from a service crash to code execution.