Citrix has issued emergency security updates for a newly exploited vulnerability affecting NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the high-severity flaw carries a CVSS 4.0 score of 8.7 and was reportedly used in targeted zero-day attacks before patches were available.
NetScaler vulnerability and impact
The flaw is caused by a memory overflow that can trigger a denial-of-service (DoS) condition. Exploitation requires customer-managed NetScaler appliances to be configured either as a SAML Service Provider or SAML Identity Provider, which can disrupt authentication and remote-access services that depend on those configurations.
Mitigation and patched builds
Citrix has urged affected customers to upgrade immediately. Fixed builds include NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 or later, alongside corresponding updated FIPS and NDcPP versions. Citrix-managed cloud services have already received the necessary updates.
Industry reaction and observed activity
The cybersecurity industry responded quickly after reports of exploitation. Administrators reportedly observed unexpected reboots even on recently patched appliances, and security researchers began investigating the new activity. Tenable has highlighted the flaw alongside a wider series of recently exploited NetScaler vulnerabilities. Sophos warned that successful exploitation can disrupt authentication and remote-access functionality, underscoring the urgency for remediation in environments that rely heavily on SAML.
Enterprises are being reminded that the incident goes beyond a single emergency patch. Organisations must continuously discover exposed infrastructure, prioritise vulnerabilities that are actively exploited and monitor critical authentication systems. According to the reporting, security at the network edge can no longer rely solely on periodic patch cycles; vulnerability intelligence and remediation must operate continuously.

