CISA has added CVE-2026-88779, a Citrix NetScaler memory overflow flaw, to its Known Exploited Vulnerabilities catalog after reports of targeted attacks causing denial of service and repeated crashes on vulnerable appliances. Citrix says the issue affects service availability on on-prem deployments using SAML with Gateway or AAA functionality, while advisories urge upgrades, IOC checks, and use of Global Deny List signatures. #CVE-2026-88779 #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #watchTowr #BishopFox #Geico
Keypoints
- CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog.
- The flaw is a Citrix NetScaler memory overflow bug that can cause denial of service.
- Citrix reported targeted attacks against unmitigated NetScaler deployments.
- The issue affects specific NetScaler ADC and Gateway versions, especially with SAML enabled.
- Citrix and CISA urged upgrades, IOC checks, and mitigation signatures to reduce exposure.