Citrix releases emergency patches for actively exploited NetScaler vulnerability

Citrix has released urgent updates addressing CVE-2026-88779, a memory buffer flaw in NetScaler ADC and Gateway appliances that is being actively exploited in targeted attacks. The vulnerability, with a CVSS score of 8.7, causes denial-of-service conditions and affects systems using SAML authentication. Security researchers are investigating whether the flaw could also enable remote code execution beyond the currently documented denial-of-service impact.
The vulnerability affects NetScaler devices that have been configured to use SAML authentication, a common enterprise security protocol. Organizations need to verify their deployment settings to determine exposure risk. Notably, this is the latest in a series of NetScaler flaws requiring urgent patching; administrators who recently installed fixes for previous vulnerabilities must now apply additional updates, creating operational strain across affected IT teams managing multiple critical infrastructure components.
Security researchers have observed evidence suggesting the flaw may enable attackers to execute arbitrary code on vulnerable systems, potentially exceeding Citrix's current damage assessment. Logs documented suspicious authentication attempts containing shell command syntax directing systems to download and run malicious files, with timing correlating to device crashes, though definitive proof of successful code execution remains under investigation.
This vulnerability could significantly impact organizations relying on NetScaler appliances for network access and authentication, particularly in sectors managing sensitive data. The active exploitation in targeted attacks suggests adversaries are already attempting to leverage the flaw before patches are universally deployed. Enterprise IT departments may face substantial operational demands managing emergency updates across distributed infrastructure, while delayed patching could expose critical systems to service disruption or potential data compromise if code execution proves viable.