Citrix patches exploited NetScaler SAML zero-day CVE-2026-88779
Citrix shipped emergency updates for NetScaler ADC and NetScaler Gateway after a zero-day SAML flaw was exploited; a CVSS 8.7 issue can cause denial of service.
Citrix has released emergency updates for NetScaler ADC and NetScaler Gateway to fix a zero-day vulnerability tracked as CVE-2026-88779, according to security outlet BleepingComputer. The flaw carries a CVSS score of 8.7 and affects appliances that use SAML authentication with Gateway or AAA functionality.
Citrix said targeted attacks against unmitigated NetScaler deployments can lead to denial of service. The company issued the fixes as NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28.
Researchers are investigating whether the flaw can also be exploited for remote code execution, according to the report. That possibility has not been confirmed.
In a Reddit thread cited in the report, an administrator said customers running NetScaler 14.1-73.37 experienced repeated forced reboots.
In background context, Citrix published a security notice on the preceding Friday stating its teams were tracking a newly observed issue related to SAML authentication. The emergency updates followed early Sunday morning, according to the article.
Quick answers
Which NetScaler versions fix CVE-2026-88779?
Citrix released NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28 to address the zero-day.
What is the severity of CVE-2026-88779?
The vulnerability has a CVSS score of 8.7 and affects appliances using SAML authentication with Gateway or AAA functionality.
What can exploitation of the flaw cause?
Citrix said targeted attacks on unmitigated NetScaler deployments can lead to denial of service; researchers are investigating whether remote code execution is also possible.