Citrix Warns of Actively Exploited NetScaler Vulnerabilities Affecting ADC and Gateway

Citrix Warns of Actively Exploited NetScaler Vulnerabilities Affecting ADC and Gateway

By Tamilselvan
Publication Date: 2026-10-05 05:00:00

Citrix has issued a high-severity security advisory for CVE-2026-88779, a memory overflow vulnerability affecting customer-managed NetScaler ADC and NetScaler Gateway appliances.

The flaw can be remotely exploited to cause a denial-of-service condition in deployments configured as a SAML Service Provider or SAML Identity Provider.

Tracked as CVE-2026-88779, the vulnerability carries a CVSS v4 base score of 8.7 and is categorized as CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer.

Citrix Warns of Actively Exploited NetScaler Vulnerabilities

Citrix said the issue requires no authentication or user interaction, increasing the urgency for organizations that expose vulnerable NetScaler infrastructure to the internet.

The vulnerability affects NetScaler ADC and NetScaler Gateway version 14.1 releases prior to 14.1-73.41 and 13.1 releases prior to 13.1-64.28. It also impacts NetScaler ADC 14.1-FIPS builds before 14.1-73.41 FIPS, as well…