Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix NetScaler security snafus get even worse amid more 0-day reports

By theregister.com
Publication Date: 2026-10-05 00:00:00

security

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service

The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found – and has already exploited – yet another Citrix bug before it had a patch.

This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. 

Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler…