Image: thaicert.or.th · rights & removal
Citrix Patches NetScaler Zero-Day Vulnerability After Active Exploitation Detected
Reporting by Thailand ThaiCERT AdvisoriesRead the original at thaicert.or.th
Executive Summary
Citrix released a security update for CVE-2026-88779, a zero-day memory buffer vulnerability affecting NetScaler ADC and NetScaler Gateway devices with SAML authentication enabled. The vulnerability is pertinent to organizations using these appliances because attacks have been observed targeting unpatched systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog and recommended prompt remediation to mitigate risks to network infrastructure.
The vulnerability has a CVSS score of 8.7. Initial reports indicated the primary impact is denial of service, leading to system process failures and device reboots, causing service unavailability. However, independent analysis from researchers suggests potential for more severe outcomes, including attempts to execute malicious commands and download malware, implying the possibility of remote code execution beyond mere service disruption.
Administrators must review NetScaler configurations to confirm if SAML functionality is enabled, specifically checking for SAML Service Provider (SP) or Identity Provider (IdP) settings. Remediation requires updating affected systems to fixed versions, specifically 14.1-73.41 or 13.1-64.28, along with corresponding supported FIPS releases. Additional protective steps involve blocking malicious IP addresses identified by the vendor and closely monitoring system logs for suspicious activity.
Facts Only
* Citrix released an emergency security update for CVE-2026-88779 on Monday, October 5, 2026.
* The vulnerability affects NetScaler ADC and NetScaler Gateway devices when SAML authentication is enabled.
* The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
* The vulnerability has a CVSS score of 8.7.
* Initial impact was reported as denial of service, causing system processes to fail and device reboots.
* Research reports indicate potential for additional activity, including attempts to execute malicious commands and download malware, suggesting remote code execution is a possibility.
* Administrators should review NetScaler configurations for enabled SAML functionality (SP or IdP).
* Affected systems must be updated to versions 14.1-73.41 or 13.1-64.28, including corresponding FIPS releases.
* Administrators should block malicious IP addresses identified by the vendor and monitor system logs for suspicious activity.
Full Take
From the original · Thailand ThaiCERT Advisories
544/69 Monday, October 5, 2026 Citrix has released an emergency security update to address CVE-2026-88779, a zero-day memory buffer vulnerability affecting NetScaler ADC and NetScaler Gateway devices with SAML authentication enabled. The vulnerability is particularly important for organizations using these appliances because attacks have been observed targeting unpatched systems.Read the full story at thaicert.or.th
Sentinel — Human
The text reads like an accurate, professionally drafted security advisory, characterized by formal structure and precise technical language, suggesting it originated from or was closely edited by a human authority.
