By James Coker
Publication Date: 2026-10-05 13:30:00
Citrix has warned of “targeted attacks” against its NetScaler ADC and NetScaler Gateway products via a new zero day vulnerability, which could lead to denial of service (DoS) for customers.
The high-severity vulnerability, CVE-2026-88779, is a memory buffer issue which can affect service availability if certain pre-conditions are met. It carries a CVSS rating of 8.7.
In a security update published on October 4, Citrix urged customers using NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 to review their configurations to determine whether Security Assertion Markup Language (SAML) authentication actions are configured.
The pre-conditions are met if their configuration contains entries matching either:
- Appliance is configured as a SAML SP add authentication samlAction, or
- Appliance is configured as a SAML IdP add authentication samlIdPProfile
Impacted customers should install updated…


