Citrix has released emergency security updates for a newly exploited vulnerability affecting NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the high-severity flaw carries a CVSS 4.0 score of 8.7 and was reportedly used in targeted zero-day attacks before patches became available.
The vulnerability is caused by a memory overflow and can trigger a denial-of-service (DoS) condition. Exploitation requires customer-managed NetScaler appliances to be configured either as a SAML Service Provider or SAML Identity Provider, potentially disrupting authentication and remote-access services.
Citrix has urged affected customers to upgrade immediately. Fixed builds include NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 or later, alongside corresponding updated FIPS and NDcPP versions. Citrix-managed cloud services have already received the necessary updates.
The cybersecurity industry is reacting aggressively. Administrators reportedly observed unexpected reboots even on recently patched appliances, while security researchers began investigating the new activity. Tenable has highlighted the flaw alongside a wider series of recently exploited NetScaler vulnerabilities.
The incident is particularly concerning because NetScaler gateways often sit at the edge of enterprise networks, handling authentication and remote connectivity. Sophos warns successful exploitation can disrupt authentication and remote-access functionality, making rapid remediation important for enterprises relying heavily on SAML.
The larger lesson goes beyond another emergency patch. Enterprises must continuously discover exposed infrastructure, prioritise actively exploited vulnerabilities and monitor critical authentication systems. Security at the network edge can no longer depend on periodic patch cycles; vulnerability intelligence and remediation must operate continuously.





