By SOC Prime Team
Publication Date: 2026-10-05 17:27:00
Only days after Citrix addressed actively exploited NetScaler flaws CVE-2026-88771 and CVE-2026-88772, defenders faced another urgent security issue. A newly disclosed vulnerability tracked as CVE-2026-88779 has been exploited in targeted attacks against customer-managed NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication.
Citrix rates the vulnerability as high severity with a CVSS v4.0 score of 8.7. The vendor describes it as a memory overflow issue that can be remotely triggered to cause denial of service without authentication or user interaction. Repeated exploitation may leave vulnerable services unavailable, creating significant operational risk for organizations relying on NetScaler for application delivery and remote access.
The vulnerability has already drawn additional attention because exploitation began while organizations were still responding to the previous NetScaler zero-days. CISA added the flaw to its…



