Citrix has issued emergency security updates to address a critical vulnerability in its NetScaler ADC and Gateway appliances. This zero-day flaw, identified as CVE-2026-88779, is being actively exploited by attackers and poses a significant risk of denial-of-service attacks. These attacks can disrupt essential services by targeting appliances configured as SAML service providers or identity providers. With a CVSS score of 8.7, this vulnerability is considered severe and requires immediate attention.
The flaw is a memory overflow issue, categorized under CWE-119, which allows attackers to disrupt services by exploiting out-of-bounds memory operations. Citrix has confirmed that while service availability is impacted, there is no evidence of data integrity being compromised. The vulnerability can be exploited over a network without user credentials or interaction, making it crucial for organizations to update vulnerable systems promptly.
Administrators have reported issues with systems rebooting repeatedly after applying previous patches. This has been linked to crafted SAML traffic causing crashes in the authentication service. Additionally, some reports indicate attempts to execute shell commands through authentication requests, although successful execution has not been confirmed.
Security researcher Kevin Beaumont and watchTowr have both highlighted potential concerns around code execution, although Citrix maintains that the primary risk is denial of service. The affected versions include NetScaler ADC and Gateway releases before 14.1-73.41 and 13.1-64.28, as well as certain FIPS releases. Citrix-managed cloud services are updated by the Cloud Software Group, but customer-managed systems require manual updates.
Organizations must verify their appliance configurations and apply the necessary updates immediately. Citrix has also provided Global Deny Lists to block known malicious IP addresses, but emphasizes that patching remains the most effective defense. Security teams should ensure they are running at least version 14.1-73.41 on the 14.1 branch or 13.1-64.28 on the 13.1 branch to protect against this vulnerability.

