Citrix issued patches over the weekend for NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28 to fix the flaw, which carries a CVSS score of 8.7. The company said it has observed targeted attacks on unmitigated deployments that lead to denial of service. "If the condition is triggered repeatedly, the service may remain unavailable," Citrix stated in a blog post. The advisory noted that the integrity of customer data has not been affected.
The vulnerability affects appliances configured as a SAML service provider or identity provider. Citrix is also providing Global Deny Lists to block known malicious IP addresses but recommends installing the security updates as soon as possible.
Organizations that recently upgraded NetScaler appliances to fix two other actively exploited zero-day vulnerabilities (CVE-2026-88771 through CVE-2026-88778) must upgrade again to address this new flaw. "If you upgraded your NetScaler deployment with one of the updated software releases ... please upgrade your deployment again," Citrix warned.
Meanwhile, NetScaler administrators and cybersecurity researchers have reported activity suggesting the flaw may enable remote code execution. Administrators on Reddit described repeated forced reboots on recently patched appliances, raising concerns that attacks may go beyond denial of service. Citrix has not confirmed code execution but analysis is ongoing.