NetScaler Zero-Day Triggers Security Alert

NetScaler Zero-Day Triggers Security Alert

By VARINDIA
Publication Date: 2026-10-06 11:31:00

Citrix has released emergency security updates for a newly exploited vulnerability affecting NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the high-severity flaw carries a CVSS 4.0 score of 8.7 and was reportedly used in targeted zero-day attacks before patches became available.

The vulnerability is caused by a memory overflow and can trigger a denial-of-service (DoS) condition. Exploitation requires customer-managed NetScaler appliances to be configured either as a SAML Service Provider or SAML Identity Provider, potentially disrupting authentication and remote-access services.

Citrix has urged affected customers to upgrade immediately. Fixed builds include NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 or later, alongside corresponding updated FIPS and NDcPP versions. Citrix-managed cloud services have already received the necessary updates.

The cybersecurity industry is reacting aggressively. Administrators reportedly observed unexpected reboots even on…