Security advisories

Actively Exploited Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-88779)

October 5, 2026

4 MINS READ

The Threat

On October 4th, 2026, Citrix disclosed the zero-day vulnerability CVE-2026-88779, impacting NetScaler ADC and NetScaler Gateway deployments. CVE-2026-88779 (CVSS: 8.7) is a memory overflow vulnerability impacting NetScaler ADC and NetScaler Gateway "under specific deployment conditions" that can lead to Denial of Service (DoS). Pre-conditions require that NetScaler deployments use SAML authentication (SAML service provider [SP] or SAML identity provider [IdP]) in conjunction with Gateway or AAA functionality.

Citrix states that they have observed "targeted attacks on unmitigated NetScaler deployments". Unconfirmed reporting has suggested that exploitation of the flaw led to Remote Code Execution (RCE). Patches have been released to address CVE-2026-88779; as exploitation is ongoing, organizations should ensure that relevant patches are applied as soon as possible.

What we're doing about it

What you should do about it

Additional information

On October 2nd, Citrix published a security update, stating that there was a "newly observed issue" relating to SAML authentication in NetScaler deployments. By October 4th, Citrix confirmed that "targeted attacks" had been observed, but no additional details were shared. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4th, giving Federal Civilian Executive Branch (FCEB) agencies a deadline of October 7th to apply relevant patches.

Following Citrix's initial update, watchTowr Labs claimed that they were "tracking rumors" and "honeypot activity" relating to a new vulnerability impacting NetScaler appliances, later claiming to have "successfully reproduced" the vulnerability. It is likely that watchTowr Labs will publish further technical details, and possibly a Proof-of-Concept (PoC) exploit, for CVE-2026-88779 in the near future, which could lower the barrier for exploitation. Further reporting on the flaw suggests that although it is characterized as a DoS, CVE-2026-88779 was escalated to achieve Remote Code Execution (RCE) and payload deployment through specially crafted authentication requests containing shell commands.

The disclosure of CVE-2026-88779 comes shortly after two other zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and NetScaler Gateway were reported. Widespread exploitation of these flaws was observed within days of their identification, demonstrating a history of NetScaler appliances being targeted within attacks. As exploitation of CVE-2026-88779 is ongoing, organizations should ensure that relevant patches are applied as soon as possible. If patching cannot immediately be applied, Citrix has released Global Deny List signatures, which can be used to "reduce exposure" while awaiting upgrades.

Fixed Versions

References

[1] https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
[2] https://nvd.nist.gov/vuln/detail/cve-2026-88779
[3] https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
[4] https://aviatrix.ai/threat-research-center/citrix-netscaler-saml-zero-day-cve-2026-88779-exploited-attacks/
[5] https://community.citrix.com/techzone-blogs/netscaler/netscaler-global-deny-list-always-on-protection-for-the-threats-you-havent-modeled-yet-r1254/#2_Unconditional_evaluation_in_the_request_pipeline__3e5a90
[6] https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
[7] https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog
[8] https://x.com/watchtowrcyber/status/2106177591438958751
[9] https://www.esentire.com/security-advisories/citrix-netscaler-adc-and-netscaler-gateway-zero-day-vulnerabilities-cve-2026-88771-cve-2026-88772
[10] https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories