On October 4, 2026, Citrix disclosed a high-severity (CVSS score of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). Successful exploitation can cause a denial of service (DoS) condition, potentially disrupting authentication services and remote access functionality. This vulnerability affects customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication services are not affected, as the required updates are applied to those platforms.
Active exploitation has been reported. Citrix has observed targeted attacks against unpatched NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) Catalog.
Recommended actions
Counter Threat Unitâ„¢ (CTU) researchers recommend that organizations identify affected systems and apply the latest Citrix security updates as soon as possible as appropriate to minimize the risk of service disruption. Organizations should prioritize internet-facing and business-critical deployments.
Sophos countermeasures
SophosLabs continues to monitor the threat landscape for activity related to this vulnerability and will deliver detections and protections as available.

