Citrix Patches Third NetScaler Zero-Day in Two Weeks
CVE-2026-88779 is a NetScaler DoS flaw exploited in zero-day attacks against SAML deployments, now in CISA KEV with a federal patch deadline of October 7.

Citrix released patches on October 4 for CVE-2026-88779, a high-severity denial-of-service flaw in NetScaler ADC and NetScaler Gateway. Attacks exploiting the vulnerability in the wild were confirmed before patches were widely applied. CISA added it to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of October 7.
This is the third actively exploited NetScaler vulnerability in approximately two weeks.
What to patch
Upgrade to the following builds immediately:
- NetScaler ADC: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282
- NetScaler Gateway: 14.1-73.41, 13.1-64.28
October 7 is the federal deadline under BOD 26-04, but it is the floor, not the target. If you run NetScaler, this needs to happen now.
The flaw
Per NVD, CVE-2026-88779 is an improper restriction of operations within a memory buffer. CVSS score: 7.5 (high). The flaw allows denial of service. BleepingComputer and SecurityWeek both report that attacks targeted SAML-enabled deployments and could knock affected appliances offline. Whether exploitation began before or immediately after Citrix issued patches is still under investigation.
Three in two weeks
Citrix patched CVE-2026-88771 and CVE-2026-88772 on September 28 following confirmed active exploitation of two remote code execution vulnerabilities. Web shell activity on unpatched appliances was still live as of September 30. CVE-2026-88779 emerged just days after those patches shipped.
If you have appliances still unpatched from the September 28 advisories, the RCE flaws are higher severity and go first. CVE-2026-88779 adds denial-of-service exposure but does not enable code execution based on current reporting.
- [ HIGH ]CVE-2026-88779Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks
Found this useful? Share it.


