Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-88779)
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) under specific deployment conditions
Summary
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) under specific deployment conditions
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.
Threat details
Active Exploitation of CVE-2026-88779
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses continued exploitation as highly likely.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
Citrix published a security advisory for a vulnerability affecting Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).
- CVE-2026-88779 - 'Memory overflow' vulnerability - CVSSv4 score: 8.7.
Successful exploitation of CVE-2026-88779 could lead to denial-of-service (DoS) when NetScaler ADC or NetScaler Gateway is be configured as a SAML SP or SAML IdP.
Remediation advice
Affected organisations should review Citrix advisory CTX697174 and apply the relevant updates as soon as possible.
Definitive source of threat updates
Last edited: 5 October 2026 2:30 pm