A serious flaw in Citrix NetScaler remote access and load balancing appliances is being actively exploited by attackers. If your business uses NetScaler to let staff connect remotely, it needs patching now.
- What it is: A memory flaw (CVE-2026-88779) in the way NetScaler handles SAML single sign-on logins. Citrix describes it as a denial-of-service issue, but researchers have seen attackers use it to download and run malicious software.
- Who is affected: Businesses running NetScaler ADC or NetScaler Gateway with SAML authentication enabled, including those that patched earlier Citrix flaws this year.
- The risk: Repeated device crashes and reboots, loss of remote access for staff, and possible takeover of the appliance as an entry point into your network.
- What to do: Update to NetScaler 14.1-73.41 or 13.1-64.28 (FIPS builds: 14.1-73.41 FIPS or 13.1-37.282), apply Citrix deny lists for known malicious addresses, and check for unexpected crashes or reboots.
We recommend booking the update with your IT provider today. If you are unsure whether your business uses NetScaler, contact OzComm and we will check for you.
Sources: BleepingComputer, CISA