Citrix has released emergency updates for CVE-2026-88779, a zero-day NetScaler memory buffer flaw that is being exploited in targeted attacks to cause denial of service, with researchers also probing whether it can lead to remote code execution. The issue affects NetScaler ADC and NetScaler Gateway appliances using SAML authentication, and CISA has added it to its Known Exploited Vulnerabilities catalog. #Citrix #NetScaler #CVE-2026-88779 #CISA
Keypoints
- Citrix released emergency fixes for CVE-2026-88779.
- The flaw affects NetScaler ADC and NetScaler Gateway with SAML authentication.
- Targeted attacks have caused denial-of-service conditions on unpatched systems.
- Researchers are investigating possible remote code execution impact.
- CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog.