Citrix issues patches for NetScaler memory overflow flaw under active attack
Citrix has released emergency security updates for a memory overflow vulnerability in its NetScaler appliances that is actively being exploited in zero-day attacks.
FTMQ Security, written by our newsroom0 views
Citrix has issued emergency software updates to fix a high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, CSO Online and BleepingComputer reported. The flaw is being actively exploited in zero-day attacks, according to BleepingComputer. [2][3]
tracked as CVE-2026-88779, the issue is a memory overflow buffer flaw that can cause a denial-of-service condition on affected appliances, CSO Online and BleepingComputer both reported. BleepingComputer noted that security researchers are currently investigating whether the vulnerability can also be leveraged by hackers for remote code execution. [2][3]
The memory buffer flaw specifically poses significant risks to users, InfoSecurity Magazine reported, adding that the Cybersecurity and Infrastructure Security Agency warned the issue impacts the federal government. The platform functions as an application delivery controller, incorporating features such as load balancing, content caching, and SSL offloading. [6][14]
As FTMQ Security reported earlier, the memory flaw affects appliances using SAML authentication with Gateway. Multiple outlets previously noted that appliances reboot repeatedly after applying emergency patches. [15]
CSO Online reported that the new warning comes just days after Citrix urged customers to patch a separate set of vulnerabilities that included two other actively exploited zero-day flaws. Citrix has urged administrators with NetScaler deployments to apply the latest updates to mitigate exploitation risks. [2]
In short
- CVE-2026-88779 is a memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway.
- The vulnerability causes a denial-of-service condition and is being actively targeted in zero-day attacks.
- Researchers are investigating if the flaw can be exploited for remote code execution.
- Citrix has released emergency patches to address the issue.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Citrix warns of actively exploited NetScaler flaw days after zero-day patch rushcsoonline.com, 20h ago (the report this story comes from)
- [2]Citrix warns of actively exploited NetScaler flaw days after zero-day patch rushCSO Online, 1d ago
- [3]Citrix patches NetScaler SAML zero-day exploited in attacksBleepingComputer, 1d ago
- [4]Citrix patches NetScaler SAML zero-day exploited in attacksBleepingComputer, 1d ago
- [5]Citrix patches NetScaler SAML zero-day exploited in attacksbleepingcomputer.com, 1d ago
- [6]Citrix NetScaler Targeted Via New Zero DayInfoSecurity Magazine, 1d ago
- [7]CVE-2026-88779: Citrix NetScaler Zero-Day Exploited in Targeted AttacksTechNadu, 1d ago
- [8]Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierSecurityWeek, 1d ago
- [9]Citrix issues patch for third exploited flaw in NetScalerCybersecurity Dive, 16h ago
- [10]Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitationSophos, 1d ago
- [11]Citrix NetScaler security snafus get even worse amid more 0-day reportsThe Register, 17h ago
Background
- [12]Comcast on Wikipedia
- [13]Coruna (exploit kit) on Wikipedia
- [14]NetScaler on Grokipedia
- [15]Citrix issues emergency updates for NetScaler zero day vulnerability FTMQ Security, 1d ago
Our newsroom writes these reports with the help of software, from the 15 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Citrix issues emergency updates for NetScaler zero day vulnerabilityTop Stories, 1d ago
- CISA adds actively exploited Citrix NetScaler zero day to KEV catalogCybercrime and Scams, 14h ago
- Cisco Warns of Active Exploitation in Critical SD-WAN Manager FlawIncident Response, 14h ago
- Microsoft Patches High Severity Privilege Escalation Flaw in Exchange ServerTop Stories, 16h ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.