Security

One crafted request can crash a NetScaler, and CISA wants it patched today

(today) · 2 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway set up for SAML, and one crafted request can crash the device
  • Citrix patched on Saturday; CISA confirmed active exploitation on Sunday, with a federal deadline of Wednesday
  • Targets so far include government, banking and professional services
  • Citrix has published interim mitigations and a script to check for compromise

Three days. That is how long it took CVE-2026-88779 to go from first exploitation reports to a confirmed federal emergency. Reports of attacks appeared late Friday, Citrix released a patch on Saturday, and CISA confirmed active exploitation on Sunday. Federal agencies have until Wednesday, which is today, to fix it.

What CVE-2026-88779 does

The Citrix NetScaler vulnerability is a memory overflow in NetScaler ADC and NetScaler Gateway appliances that are set up for SAML authentication, either as a service provider or an identity provider. One specially crafted request is enough to crash the device. In plain terms, an attacker can knock your login front door offline, and everyone who relies on it for access goes with it.

WatchTowr's Jake Knott said the flaw is "incredibly simple to trigger" and that exploitation is already happening. That is the kind of sentence that should move a patch up your list.

Why this one is worse than a crash

A crash sounds minor next to remote code execution, but the context matters. Researchers suspect this bug could help attackers move faster on CVE-2026-88771, one of eight NetScaler flaws disclosed on 27 September. Two of those eight were exploited for weeks before anyone knew. Targets so far are government bodies, banks and professional services firms.

An appliance that sits in front of everything is a good place to cause a lot of damage with very little effort. If you want the general playbook for this kind of bug, our zero-day network device checklist covers the seven steps, and the same pattern showed up in the Zimbra critical email vulnerability.

What to do now

Install the patched NetScaler build. If you cannot upgrade today, apply Citrix's interim mitigation. Then run the indicator-of-compromise script Citrix published to check whether anyone got there first. Start with appliances configured as Gateway or AAA virtual servers with SAML enabled, since those are the ones exposed to this bug.

Because earlier NetScaler flaws were exploited before disclosure, a clean patch does not prove a clean box. Check logs from before 27 September, and keep an eye on Citrix for further advisories.

More from Future Technology