Attackers are actively exploiting a newly disclosed flaw in Citrix NetScaler remote access and load-balancing appliances, causing them to crash and reboot. The US cyber agency CISA added it to its Known Exploited Vulnerabilities list on 5 October 2026.
- What it is: A memory flaw (CVE-2026-88779) that lets an attacker knock a NetScaler offline. Attackers have also been seen trying to download scripts onto affected devices.
- Who is affected: Businesses running their own (on-premises) NetScaler ADC or Gateway, versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, with SAML single sign-on or AAA authentication configured.
- The risk: Repeated crashes can cut off staff who rely on the appliance for remote access to email, files and business applications.
- What to do: Upgrade to the fixed firmware versions, and apply Citrix's published blocklist signatures to block known malicious addresses while you plan the upgrade.
We recommend businesses using NetScaler check their firmware version today and contact us if you need help patching or confirming whether you are exposed.
Sources: Help Net Security, CISA Known Exploited Vulnerabilities Catalog