Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush
Brief
Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days. The new vulnerability, tracked as CVE-2026-88779, is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Citrix rated it 8.
7 under CVSS 4. 0 and said it has observed targeted attacks against unmitigated NetScaler deployments. The company said the attacks can repeatedly trigger the condition, potentially leaving the service unavailable. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met,” the company said in a blog post.
