Citrix issues emergency updates for NetScaler zero day vulnerability
Citrix has released emergency security patches for a zero-day vulnerability in NetScaler ADC and Gateway appliances that is under active exploitation.
FTMQ Security, written by our newsroom0 views

Citrix has released emergency security updates for a zero-day vulnerability tracked as CVE-2026-88779 in NetScaler ADC and NetScaler Gateway appliances, BleepingComputer reported. The flaw has already seen active exploitation in zero-day attacks. [1][2]
The vulnerability involves a memory buffer flaw that affects appliances configured to use Security Assertion Markup Language authentication with Gateway. According to BleepingComputer, the security flaw causes denial-of-service conditions, while researchers are actively investigating whether attackers can leverage it for remote code execution. [1]
Reports from CyberSecurityNews and GBHackers indicate that NetScaler appliances have been observed rebooting repeatedly following the installation of the zero-day patch. Security Assertion Markup Language metadata standard, which defines deployment configurations for trust and interoperability, was published by OASIS in 2005. [3][7][8]
System administrators using affected NetScaler ADC and Gateway instances are advised to apply the emergency security updates provided by Citrix immediately to mitigate potential crash triggers and remote exploitation attempts. [1][6]
In short
- Citrix released emergency updates for a zero-day denial-of-service vulnerability tracked as CVE-2026-88779.
- The memory buffer flaw affects NetScaler ADC and Gateway appliances using SAML authentication with Gateway.
- Researchers are investigating if the flaw allows remote code execution.
- Multiple outlets reported that NetScaler appliances reboot repeatedly after applying the emergency patch.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Citrix patches NetScaler SAML zero-day exploited in attacksBleepingComputer, 3h ago (the report this story comes from)
- [2]Citrix patches NetScaler SAML zero-day exploited in attacksbleepingcomputer.com, 3h ago
- [3]Citrix NetScaler Keeps Rebooting Following the 0-Day PatchCyberSecurityNews, 11h ago
- [4]Active Exploitation Alert: Zero-Day Vulnerabilities in Citrix NetScaler and Kiteworks Impact Critical Infrastructure (CVE-2026-88771, CVE-2026-88772)Rescana, 10h ago
- [5]New Citrix NetScaler SAML Flaw Triggers Crashes and Suspected Exploitation Attemptscyberpress.org, 1d ago
- [6]Update Citrix Netscaler now: Zero-day causes crashes and code executionheise online, 1d ago
- [7]Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Updategbhackers.com, 1d ago
Background
- [8]SAML metadata on Wikipedia
- [9]Timeline of computer viruses and worms on Wikipedia
Our newsroom writes these reports with the help of software, from the 9 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
More in Top Stories
- China Aligned TA419 Targets US AI Experts With Phishing Attacks1h ago
- Suspected ShinyHunters Hacker Detained in Jordan Cooperating With FBI8h ago
- Anthropic requests voice conversation data from Claude users for model training8h ago
- Donald Trump Appoints National Intelligence Director Jay Clayton to Head AI Task Force8h ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.