Skip to content
theregister·

🚨NetScaler Vulnerability CVE-2026-88779 Exploited in Wild

NetScaler Vulnerability Exploited, Patches Urgent

TL;DR

A critical vulnerability in NetScaler ADC and Gateway appliances is actively exploited, leading to denial of service. Citrix urges immediate patching to prevent attacks.

A new vulnerability, tracked as CVE-2026-88779, is causing denial of service attacks on NetScaler ADC and Gateway appliances. The vulnerability, confirmed by Citrix on Saturday, affects configurations with SAML service provider or identity provider settings. CISA has ordered federal agencies to patch the bug by Wednesday. Security teams should prioritize appliances with SAML authentication enabled. The vulnerability is simple to trigger, requiring just a single crafted request to knock an appliance offline. Citrix released a security advisory with patches and an indicator-of-compromise script.

NetScaler Vulnerability CVE-2026-88779 Exploited in Wild — theregister

Key Points

1

CVE-2026-88779 affects NetScaler ADC and Gateway appliances configured as SAML service provider or identity provider.

2

Citrix confirmed the vulnerability on Saturday amid exploitation reports.

3

CISA ordered federal agencies to patch the bug by Wednesday.

4

Citrix released a security advisory with patches and an IoC script.

5

WatchTowr and Bishop Fox helped Citrix address the issue.

Why It Matters

If you're using NetScaler ADC or Gateway appliances with SAML authentication, this vulnerability is a critical threat. Disrupting an authentication gateway can prevent legitimate users from accessing services. Affected organizations should apply the fixed build or Citrix's interim mitigation immediately.

NetScalerCVE-2026-88779CitrixCISASAML

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Also get