NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Citrix Patches Third Actively Exploited NetScaler Zero Day

Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were released for two other actively exploited zero day flaws. Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. The former is often used to provide cloud applications to employees, while the latter is commonly used as an SSL VPN to provide single sign-on to remote workers.

The previously patched two zero-days can lead to remote code execution; however, the latest vulnerability is believed to only allow an attacker to crash the system, with repeated attacks resulting in denial of service. Citrix explained that it has observed targeted attacks on unmitigated NetScaler systems and has yet to determine the impact on the integrity of customer data. Security researchers have found evidence that threat actors are chaining one of the earlier RCE zero day flaws – CVE-2026-8877 – with the latest vulnerability.

The vulnerability is tracked as CVE-2026-88779 and is rated high severity, with a CVSS v4.0 severity score of 8.7. The flaw is a memory overflow vulnerability in SAML that affects customer-managed deployments configured as a SAML Service Provider (SAML SP / SAML IdP). Citrix also warned that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have been automatically updated with the fixed version.

Patches to fix the vulnerability were issued on October 4, 2026. Users who have already patched the previous two zero days will also need to apply the latest fix to protect against exploitation. Citrix is urging all customers with vulnerable appliances to upgrade to the fixed version as soon as possible. Further information can be found in the Citrix security bulletin.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Vulnerable versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
  • Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282

Patched versions:

  • NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
  • NetScaler ADC / NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist