By Interestana AI Editorial — AI-drafted, human-overseen. How we report
NetScaler Zero-Day Vulnerability Exploited in Targeted Attacks

Citrix has issued security advisories and patches for a critical zero-day vulnerability affecting its NetScaler ADC and NetScaler Gateway products. This flaw, identified as CVE-2026-88779, has already been actively exploited in targeted cyberattacks, posing a significant risk to organizations relying on these solutions for secure access and authentication. The vulnerability is classified as a memory overflow flaw, and it carries a high severity rating with a CVSS score of 8.7 out of 10.0, indicating a substantial potential for damage and exploitation.
The primary impact of exploiting CVE-2026-88779 is the ability for an unauthenticated attacker to gain administrative access to the affected NetScaler appliances. This level of access allows for significant disruption, including the potential to knock Secure Assertion Markup Language (SAML) deployments offline. SAML is a widely adopted standard for exchanging authentication and authorization data between parties, typically between an identity provider and a service provider. By disrupting SAML, attackers can effectively prevent users from accessing critical applications and services that rely on this authentication mechanism, leading to widespread service outages and operational paralysis for affected organizations.
Citrix has confirmed that the vulnerability is present in NetScaler ADC and NetScaler Gateway versions 13.x and 14.x. The company has released specific build numbers for the patched versions, urging customers to upgrade immediately to mitigate the risk. For NetScaler ADC, versions 13.2-53.16 and 13.1-64.15 are now considered secure. For NetScaler Gateway, versions 13.2-53.16 and 13.1-64.15 also address the vulnerability. The company's advisory also notes that specific versions of NetScaler ADC and Gateway running on the NetScaler CPX form factor and NetScaler ADC VPX running on specific cloud platforms are also affected and require patching.
While Citrix has not disclosed the exact nature of the targeted attacks or the specific entities that have been compromised, the exploitation of a zero-day vulnerability signifies that attackers had knowledge of the flaw before a patch was publicly available. This underscores the importance of proactive security measures, including robust monitoring and rapid patching, especially for critical infrastructure components like NetScaler. Organizations using NetScaler ADC and NetScaler Gateway are strongly advised to consult Citrix's official security bulletins and apply the necessary updates without delay to protect their systems from further exploitation and potential data breaches or service disruptions.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.