Citrix has warned of “targeted attacks” against its NetScaler ADC and NetScaler Gateway products via a new zero day vulnerability, which could lead to denial of service (DoS) for customers.
The high-severity vulnerability, CVE-2026-88779, is a memory buffer issue which can affect service availability if certain pre-conditions are met. It carries a CVSS rating of 8.7.
In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.
The pre-conditions are met if their configuration contains entries matching either:
- Appliance is configured as a SAML SP add authentication samlAction, or
- Appliance is configured as a SAML IdP add authentication samlIdPProfile
Impacted customers should install updated versions of ADC and Gateway as soon as possible.
Citrix has also released signatures which customers can deploy to reduce exposure while they plan to upgrade to a version containing a fix. These can be used via the NetScaler Global Deny List feature.
Citrix said the integrity of customer data had not been impacted because of the flaw.
The software company will continue to monitor vulnerability activity and provide updates as needed.
The US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on October 4.
The agency warned that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”
The agency has instructed federal agents to apply Citrix’s mitigations by Wednesday October 7.
Citrix in the Spotlight Following Raft of Vulnerability Disclosures
The latest update follows a security bulletin published by Citrix on September 27, which confirmed eight zero day flaws in ADC and Gateway. This included two critical CVEs under active exploitation.
Another memory overflow flaw affecting the two products, CVE-2026-8452, was added to CISA’s KEV list on August 26.
Dan Andrew, head of security at Intruder, said that it is not uncommon for a string of vulnerabilities in particular products to come to the surface in quick succession.
“This is likely due to renewed scrutiny by researchers on the product, including those looking to reproduce the work of whoever found it first, and attackers doing the same,” he noted.
Image credit: Casimiro PT / Shutterstock.com
