🚨NetScaler Vulnerability CVE-2026-88779 Exploited in Wild
NetScaler Vulnerability Exploited, Patches Urgent
TL;DR
A critical vulnerability in NetScaler ADC and Gateway appliances is actively exploited, leading to denial of service. Citrix urges immediate patching to prevent attacks.
A new vulnerability, tracked as CVE-2026-88779, is causing denial of service attacks on NetScaler ADC and Gateway appliances. The vulnerability, confirmed by Citrix on Saturday, affects configurations with SAML service provider or identity provider settings. CISA has ordered federal agencies to patch the bug by Wednesday. Security teams should prioritize appliances with SAML authentication enabled. The vulnerability is simple to trigger, requiring just a single crafted request to knock an appliance offline. Citrix released a security advisory with patches and an indicator-of-compromise script.

Key Points
CVE-2026-88779 affects NetScaler ADC and Gateway appliances configured as SAML service provider or identity provider.
Citrix confirmed the vulnerability on Saturday amid exploitation reports.
CISA ordered federal agencies to patch the bug by Wednesday.
Citrix released a security advisory with patches and an IoC script.
WatchTowr and Bishop Fox helped Citrix address the issue.
Why It Matters
If you're using NetScaler ADC or Gateway appliances with SAML authentication, this vulnerability is a critical threat. Disrupting an authentication gateway can prevent legitimate users from accessing services. Affected organizations should apply the fixed build or Citrix's interim mitigation immediately.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.