Critical NetScaler Memory Vulnerability Under Active Attack, CISA Warns

CISA has added CVE-2026-88779, a memory overflow vulnerability in Citrix NetScaler appliances, to its Known Exploited Vulnerabilities catalog after observing targeted denial-of-service attacks. The flaw enables attackers to crash vulnerable NetScaler ADCs and Gateways, potentially rendering services unavailable, though data integrity remains unaffected according to Citrix's analysis. Affected organizations should upgrade to patched versions or apply Global Deny List signatures to reduce exposure while planning remediation.
The vulnerability affects NetScaler appliances running specific software versions, with exploitation possible only when SAML authentication is enabled alongside Gateway or AAA services. Citrix has released both patched versions and temporary signature-based protections through its Global Deny List feature to help organizations reduce risk during their upgrade process. Researchers from Bishop Fox and watchTowr initially discovered the flaw, though full technical details remain undisclosed to prevent widespread exploitation.
This vulnerability could disrupt services for organizations relying on NetScaler for network access and authentication, particularly enterprises using SAML-based identity management. While data integrity appears unprotected, availability attacks could impact employee productivity and customer-facing systems. Federal agencies face a tight remediation deadline, which may strain IT resources across government. Organizations with unpatched deployments may experience extended downtime if targeted, making prompt upgrades and threat detection critical for operational resilience.