NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SAML authentication paths and can cause denial of service on unmitigated deployments. Citrix said researchers are also investigating whether the flaw can be pushed to remote code execution. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
Related Happenings
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector Action
H score34
First: 31.03.2026 10:05
Last: 31.03.2026 10:05
Sources 1
About this happening:
CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector ActionAbout this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Latest development: 31.07.2026 20:35
Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
Timeline
-
05.10.2026 00:58 2 articles · 2h ago
Patched NetScaler appliances reboot after suspicious SAML requests
Detection Ioc UpdateNetScaler administrators reported on Thursday that recently patched appliances were unexpectedly rebooting, including systems running 14.1-73.37 and rebuilt from fresh images. The crash pattern involved repeated nsaaad and Pitboss failures on customer devices.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 1 articles · 2h ago
Citrix releases emergency NetScaler ADC and Gateway fixes for CVE-2026-88779
Mitigation Patch UpdateEarly Sunday morning, Citrix released NetScaler ADC 14.1-73.41 and 13.1-64.28 to fix CVE-2026-88779. The company also directed FIPS and NDcPP customers to install 14.1-73.41 FIPS or 13.1-37.282 and said Global Deny Lists would block access from known malicious IP addresses.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 1 articles · 2h ago
Patched NetScaler honeypots run downloaded payloads amid possible remote code execution
Technical Analysis UpdateOn Sunday, researchers and administrators saw activity suggesting CVE-2026-88779 could extend beyond denial of service. One administrator said crafted SAML authentication usernames appeared to run shell commands that download a payload from 213.209.159[.]55, save it as /v, and execute the file, while another patched honeypot was observed running a downloaded malware payload.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58
-
05.10.2026 00:58 1 articles · 2h ago
CISA adds CVE-2026-88779 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateOn Sunday, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and setting an October 7 mitigation deadline for FCEB agencies.
Show sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — www.bleepingcomputer.com — 05.10.2026 00:58