Citrix Patches NetScaler Zero-Day Vulnerability After Active Exploitation Detected
544/69 Monday, October 5, 2026
Citrix has released an emergency security update to address CVE-2026-88779, a zero-day memory buffer vulnerability affecting NetScaler ADC and NetScaler Gateway devices with SAML authentication enabled. The vulnerability is particularly important for organizations using these appliances because attacks have been observed targeting unpatched systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog and urged affected organizations to remediate the issue promptly to reduce risks to network infrastructure.
The vulnerability has a CVSS score of 8.7. Citrix initially stated that the primary impact is denial of service, which could cause system processes to fail and affected devices to repeatedly reboot, making services unavailable. However, cybersecurity researchers and independent analysts have reported additional suspicious activity observed through honeypot analysis, including attempts to execute malicious commands and download malware onto affected systems. These findings suggest that attackers may potentially be able to exploit the vulnerability for remote code execution, in addition to causing service disruption.
Administrators should immediately review their NetScaler configurations to determine whether SAML functionality is enabled, including SAML Service Provider (SP) or SAML Identity Provider (IdP) configurations. Affected systems should be updated to the latest fixed versions, including 14.1-73.41 or 13.1-64.28, as well as the corresponding supported FIPS releases. Organizations that recently updated their devices to address other vulnerabilities may still need to apply another update specifically for this issue. Administrators should also block malicious IP addresses identified by the vendor and closely monitor system logs for suspicious activity to reduce the risk of compromise and strengthen network security.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.