Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw, tracked as CVE-2026-88779, could allow unauthenticated remote attackers to cause persistent denial-of-service conditions. The vulnerability specifically affects appliances configured for SAML... Weiterlesen: Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote Do…
Intelligence View
⚡ tsecurity.de Intelligence
Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks
Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw,…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-88779
NVD: AnalyzedNVD 7.5 · HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD-Datenstand: 05.10.2026, 13:35 UTC
Ausnutzung beobachtet: Ja — aktiv Automatisierbar: Ja Technischer Impact: Teilweise
CISA KEV seit 04.10.2026 Frist: 07.10.2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
BSI-Warnung (Deutschland)CVE-2026-88779
Citrix NetScaler ADC und Gateway: Schwachstelle ermöglicht Denial of Service hoch04.10.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-88779
Exploitation: active (Aktiv ausgenutzt)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-04T19:34:09.964186Z · CISA Coordinator
Advisory Radar
Kritischer Zero-Day / Ohne Upstream-Patch
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencesupport.citrix.com