Citrix has released patches for a newly disclosed NetScaler vulnerability after reports of active attacks, and CISA has ordered federal agencies to remediate it within days.
The flaw, tracked as CVE-2026-88779, is a memory overflow bug that causes denial of service. It affects NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, the setup used for single sign-on authentication.
Citrix said it was alerted to the issue late last week and confirmed it was investigating a "newly observed issue related to SAML authentication in customer-managed NetScaler deployments." By Saturday night the vendor had released a security advisory with patches, urging customers to "install the relevant updated versions as soon as possible."
"We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson said. "After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix."
Security researchers at watchTowr, who reproduced the vulnerability and were credited by Citrix along with Bishop Fox for helping address it, said the bug is trivially easy to trigger. "This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline," said Jake Knott, watchTowr's head of threat intelligence. "Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it."
watchTowr suspects the denial-of-service bug has been used to deliberately crash machines, making exploitation of an earlier NetScaler vulnerability, CVE-2026-88771, faster. That flaw is among eight CVEs Citrix disclosed on September 27, weeks after attackers began abusing two of them.
Knott noted that Citrix provides an indicator-of-compromise script for exposed appliances, though "a clean result is not definitive proof." He urged security teams to prioritize appliances configured as Gateway or AAA virtual servers with SAML enabled, and to apply the fixed build or Citrix's interim mitigation if an immediate upgrade is not possible.
Citrix did not answer questions about how many instances have been affected or what attackers are doing after exploiting the bug.