Citrix Patches Actively Exploited NetScaler SAML Flaw; CISA Orders Urgent Remediation
Citrix released emergency updates for CVE-2026-88779, an actively exploited memory-buffer bounds vulnerability affecting NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication with Gateway or AAA functionality. The flaw has a reported CVSS score of 8.7 and can cause denial of service through repeated process crashes and appliance reboots. Administrators observed shell commands embedded in authentication usernames, while researcher Kevin Beaumont reported a downloaded malware binary running on a patched honeypot; remote code execution through this specific vulnerability remains under investigation.
- Norway's NSM updates NetScaler advisory to acknowledge denial-of-service impact
- watchTowr Labs reports reproducing CVE-2026-88779


