Citrix security patch release for CVE-2026-88779
Security Patch Release
Summary
Hide ▲
Show ▼
Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS deployments. The vendor shipped 14.1-73.41 and 13.1-64.28, and told customers to install the updates immediately. Global Deny Lists were also provided as a supplementary block list for known malicious IPs.
Related Happenings
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix security patch release for CVE-2026-13474
Security Patch Release
H score35
First: 01.07.2026 06:54
Last: 01.07.2026 06:54
Sources 1
About this happening:
Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could enable arbitrary file reads or denial of servi...
Citrix security patch release for CVE-2026-13474
Security Patch ReleaseAbout this happening: Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could enable arbitrary file reads or denial of servi...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
H score44
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch ReleaseAbout this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Latest development: 21.05.2026 12:52
Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector Action
H score34
First: 31.03.2026 10:05
Last: 31.03.2026 10:05
Sources 1
About this happening:
CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector ActionAbout this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Latest development: 31.07.2026 20:35
Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
Timeline
-
05.10.2026 00:58 1 articles · 2h ago
Patched NetScaler appliances begin rebooting during suspected exploitation
Initial DisclosureNetScaler administrators reported that recently patched NetScaler ADC and NetScaler Gateway appliances were unexpectedly rebooting, including multiple customers running NetScaler 14.1-73.37 and appliances rebuilt from fresh images. The reboot pattern suggested either a new flaw or active exploitation, while the root cause was still unclear.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 1 articles · 2h ago
Crafted SAML usernames trigger nsaaad crashes on patched NetScaler appliances
Exploitation ObservedAs administrators continued investigating the crashes, Citrix published a security notice on Friday saying its engineering and support teams were tracking a newly observed issue in customer-managed NetScaler deployments configured with authentication samlAction or authentication samlIdPProfile. One administrator saw crafted authentication usernames containing shell commands that downloaded a payload from 213.209.159[.]55, saved it as /v, and executed the file immediately before three confirmed nsaaad crash sequences on one appliance, and other researchers reported patched NetScaler honeypots crashing after requests from multiple source IP addresses. Kevin Beaumont later said one patched honeypot was running a downloaded malware payload, suggesting the flaw could go beyond denial of service.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 2 articles · 2h ago
Citrix ships emergency NetScaler fixes for CVE-2026-88779
Mitigation Patch UpdateEarly Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix CVE-2026-88779. For FIPS deployments, customers were told to upgrade to 14.1-73.41 FIPS or 13.1-37.282 on the 13.1 branch, and Citrix also provided Global Deny Lists that block access from known malicious IP addresses while urging customers to install the security updates immediately.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 1 articles · 2h ago
CISA adds CVE-2026-88779 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateOn Sunday, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming the flaw was being actively exploited and giving FCEB agencies until October 7 to mitigate it.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58