Citrix patches NetScaler zero-day flaw exploited in attacks
Citrix has issued emergency fixes for a NetScaler vulnerability (CVE-2026-88779) actively exploited in zero-day attacks targeting appliances using SAML authentication. The flaw, with a CVSS score of 8.7, can lead to denial-of-service and has caused repeated service outages. Citrix urges affected organizations to immediately install the latest updates and warns that devices recently patched for other issues must be updated again. Researchers are investigating whether the bug could also be used for remote code execution.
Why it mattersNetScaler appliances are widely used in enterprise networks. This vulnerability, if left unpatched, can disrupt critical services and may pose a larger security risk if attackers find a way to execute code remotely.
- CVE-2026-88779 exploited in ongoing attacks
- Affects NetScaler ADC and Gateway with SAML authentication
- Leads to service outages and repeated reboots
- Patches available for affected software versions
- Remote code execution risk is being investigated
Sources covering this
More in Cybersecurity
Google suspends open source bug bounty program over invalid AI submissions
Google has suspended its Open Source Software Vulnerability Reward Program after a surge in invalid or hallucinated bug reports…