CISA KEV: Actively Exploited Citrix NetScaler Zero-Day Crashes Appliances
CISA adds CVE-2026-88779, an actively exploited Citrix NetScaler memory overflow, to KEV. Patch ADC/Gateway now and restrict SAML/management access.
- CISA added CVE-2026-88779, a Citrix NetScaler ADC/Gateway memory overflow, to its Known Exploited Vulnerabilities catalog after evidence of active zero-day exploitation.
- Attackers can crash appliances and disrupt SAML/remote access; researchers are investigating possible RCE, but denial of service is confirmed.
- K-12 and government teams should patch internet-facing NetScaler systems immediately, restrict management/SAML exposure, and hunt for crashes or configuration changes.
What to do now
- Inventory all NetScaler ADC/Gateway instances, versions, and exposure; apply Citrix emergency updates for CVE-2026-88779 as an emergency change, prioritizing internet-facing and SAML/AAA appliances.
- If patching is delayed, implement Citrix mitigations, disable or tightly restrict SAML endpoints and remote access, and limit management interfaces to trusted admin networks or VPN with MFA.
- Monitor NetScaler and SAML logs for memory exhaustion, unexpected restarts, crash events, anomalous assertions, authentication failures, new accounts, scheduled tasks, outbound connections, or configuration changes.
- Segment appliances from critical internal networks; enforce least privilege and MFA for all NetScaler-mediated SSO; prepare fallback authentication for SAML outages.
- If compromise is suspected, isolate, preserve evidence, rotate credentials/tokens/certificates/secrets, rebuild rather than only patch, and report to CISA/Citrix and your incident response team. Also track CVE-2026-88771/88772 if applicable.
Related items
- Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
- Citrix patches NetScaler SAML zero-day exploited in attacks
- U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog
- CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
- Citrix NetScaler security snafus get even worse amid more 0-day reports
- CISA Adds One Known Exploited Vulnerability to Catalog