CISA KEV: Actively Exploited Citrix NetScaler Zero-Day Crashes Appliances

CISA adds CVE-2026-88779, an actively exploited Citrix NetScaler memory overflow, to KEV. Patch ADC/Gateway now and restrict SAML/management access.

  • CISA added CVE-2026-88779, a Citrix NetScaler ADC/Gateway memory overflow, to its Known Exploited Vulnerabilities catalog after evidence of active zero-day exploitation.
  • Attackers can crash appliances and disrupt SAML/remote access; researchers are investigating possible RCE, but denial of service is confirmed.
  • K-12 and government teams should patch internet-facing NetScaler systems immediately, restrict management/SAML exposure, and hunt for crashes or configuration changes.

What to do now

  1. Inventory all NetScaler ADC/Gateway instances, versions, and exposure; apply Citrix emergency updates for CVE-2026-88779 as an emergency change, prioritizing internet-facing and SAML/AAA appliances.
  2. If patching is delayed, implement Citrix mitigations, disable or tightly restrict SAML endpoints and remote access, and limit management interfaces to trusted admin networks or VPN with MFA.
  3. Monitor NetScaler and SAML logs for memory exhaustion, unexpected restarts, crash events, anomalous assertions, authentication failures, new accounts, scheduled tasks, outbound connections, or configuration changes.
  4. Segment appliances from critical internal networks; enforce least privilege and MFA for all NetScaler-mediated SSO; prepare fallback authentication for SAML outages.
  5. If compromise is suspected, isolate, preserve evidence, rotate credentials/tokens/certificates/secrets, rebuild rather than only patch, and report to CISA/Citrix and your incident response team. Also track CVE-2026-88771/88772 if applicable.

Related items