Citrix releases critical security patch for NetScaler ADC and Gateway
Citrix has released a critical security update to address a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway instances.
FTMQ Security, written by our newsroom0 views
Citrix has issued a critical security warning and patch for customers managing NetScaler ADC and NetScaler Gateway instances. CSO Online reported that this is the third consecutive week Citrix has released a critical security advisory for these products. Network World and CyberSecurityNews both report that the critical patch addresses a new remote code execution flaw. [1][2][3]
According to CSO Online, the flaw is a memory overflow vulnerability that enables denial of service or remote code execution. The vulnerability affects NetScaler ADC and NetScaler Gateway when the systems are configured as a Security Assertion Markup Language identity provider. CSO Online noted that older versions are also vulnerable when configured for SAML identity provider functions. [2]
NetScaler is a line of networking products owned by Cloud Software Group, which was formed following a private merger in 2022. As FTMQ Security reported earlier, Citrix previously released emergency updates for a zero-day denial of service vulnerability in NetScaler ADC and Gateway tracked as CVE-2026-88779. [4][5]
Citrix urges customers who manage their own NetScaler ADC and NetScaler Gateway instances to apply the security updates immediately, according to CyberSecurityNews and CSO Online. Security teams must update vulnerable instances to prevent potential service disruptions or unauthorized code execution. [2][3]
In short
- Citrix released a critical security patch for a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
- The vulnerability enables denial of service or remote code execution when appliances are configured as a SAML identity provider.
- This marks the third consecutive week that Citrix has issued a critical security warning for NetScaler appliances.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]This week’s critical patch for NetScaler ADC and NetScaler Gateway is hereNetwork World, 12h ago (the report this story comes from)
- [2]Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler GatewayCSO Online, 12h ago
- [3]Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE VulnerabilityCyberSecurityNews, 23h ago
Background
- [4]NetScaler on Wikipedia
- [5]Citrix issues emergency updates for NetScaler zero day vulnerability FTMQ Security, 5d ago
Our newsroom writes these reports with the help of software, from the 5 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Citrix issues emergency updates for NetScaler zero day vulnerabilityTop Stories, 5d ago
More in Bugs and Patches
- Citrix issues emergency patch for critical NetScaler vulnerability2h ago
- Proof of concept exploit released for critical VMware VMXNET3 security flaw1d ago
- Security researchers demonstrate zero day vulnerabilities at Pwn2Own Ireland 20261d ago
- Citrix issues patches for NetScaler memory overflow flaw under active attack4d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.