Citrix issues patch for third exploited flaw in NetScaler

Citrix issues patch for third exploited flaw in NetScaler

By David Jones
Publication Date: 2026-10-05 10:42:00

Citrix on Saturday urged customers to immediately patch a memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway, which was being exploited as a zero-day.

The vulnerability, tracked as CVE-2026-88779, could lead to a denial-of-service condition on customer-managed NetScaler deployments when certain preconditions were met, the company said. 

Citrix said it observed targeted attacks on unmitigated NetScaler systems and noted the system could be rendered unavailable in cases where repeated attacks had taken place. Citrix added it has not fully identified how these attacks could impact the integrity of customer data. 

The preconditions are based on whether NetScaler deployments are authenticated using security assertion markup language in conjunction with Gateway or AAA functionality. 

The Cybersecurity and Infrastructure Security Agency on Sunday added CVE-2026-88779 to its Known Exploited Vulnerabilities…