Citrix Patches Third Actively Exploited NetScaler Zero Day
Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were released for two other actively exploited zero day flaws. Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. The former is often used to provide cloud applications to employees, while the latter is commonly used as an SSL VPN to provide single sign-on to remote workers.
The previously patched two zero-days can lead to remote code execution; however, the latest vulnerability is believed to only allow an attacker to crash the system, with repeated attacks resulting in denial of service. Citrix explained that it has observed targeted attacks on unmitigated NetScaler systems and has yet to determine the impact on the integrity of customer data. Security researchers have found evidence that threat actors are chaining one of the earlier RCE zero day flaws – CVE-2026-8877 – with the latest vulnerability.
The vulnerability is tracked as CVE-2026-88779 and is rated high severity, with a CVSS v4.0 severity score of 8.7. The flaw is a memory overflow vulnerability in SAML that affects customer-managed deployments configured as a SAML Service Provider (SAML SP / SAML IdP). Citrix also warned that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have been automatically updated with the fixed version.
Patches to fix the vulnerability were issued on October 4, 2026. Users who have already patched the previous two zero days will also need to apply the latest fix to protect against exploitation. Citrix is urging all customers with vulnerable appliances to upgrade to the fixed version as soon as possible. Further information can be found in the Citrix security bulletin.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Vulnerable versions:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
- Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
- Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282
Patched versions:
- NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
- NetScaler ADC / NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases


