Citrix NetScaler Zero-Day Is Knocking Login Systems Offline
A memory flaw in NetScaler ADC and Gateway, now exploited in the wild, can crash the gateways many companies rely on for single sign-on. US federal agencies have three days to patch.

Key points
- A newly disclosed flaw in Citrix NetScaler, tracked as CVE-2026-88779, is already being used in targeted attacks and can knock login gateways offline, hitting the single sign-on (SSO) systems staff use to reach work apps.
- The US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalogue on 2026-10-04 and gave federal agencies until 2026-10-07 to install the fix.
- Rated 8.7 out of 10 on the industry severity scale, the flaw is a memory overflow vulnerability in both NetScaler ADC and NetScaler Gateway, and Citrix has shipped fixed builds.
- Multi-factor authentication doesn't help here, because the attack crashes the login box itself rather than guessing a password.
- Admins should patch, then check for signs that attackers reached the device before the update went on.
Citrix has pushed emergency fixes for a flaw in its NetScaler login gateways that attackers are already using in the wild. The bug is a memory overflow: the device mishandles a chunk of data in its own memory, and a crafted request can tip it into a crash.
The box that lets staff sign in once and reach every work app can be forced offline by a stranger on the internet. No password needed.
CVE-2026-88779 carries a CVSS score of 8.7 out of 10. We first covered NetScaler security on 27 September 2026, when researchers at watchTowr found attackers breaking into unpatched boxes before any fix existed. That this vendor is back in the same conversation one week later, now with a patch but also with confirmed targeted exploitation, should focus minds.
What is actually broken?
A memory overflow in the NetScaler software lets a remote attacker crash the appliance. NetScaler ADC and NetScaler Gateway are the hardware or virtual boxes that sit at a company's edge and handle sign-in traffic, including SAML (the Security Assertion Markup Language standard that carries identity between a company's login system and apps like Salesforce or Workday).
When the gateway falls over, SAML sign-in falls over with it. Staff get bounced to error pages. Help desks light up.
It's a denial-of-service bug, not a data-theft bug on its face. That still matters, because for most firms the NetScaler is the front door to every cloud app they own.
Who needs to act, and by when?
Anyone running a vulnerable build of NetScaler ADC or Gateway. US federal civilian agencies have a hard deadline of 2026-10-07 under the CISA directive. Everyone else should treat that as a sensible ceiling, not a target.
Citrix has confirmed fixed builds exist; consult the vendor advisory directly for exact version strings, as Threat Vectr won't publish numbers that aren't verified in the CVE record. CISA added the bug to its Known Exploited Vulnerabilities catalogue on 2026-10-04, the agency's formal signal that attacks aren't theoretical.
Would MFA have helped?
Honestly, no. Multi-factor authentication, the second step where you approve a login on your phone, protects against someone stealing or guessing a password. This bug doesn't touch passwords. It crashes the gateway that would ask for the password in the first place.
Auth, proving who you are, and authz, deciding what you're allowed to do, both run through this appliance. Knock it over and neither works.
What should ordinary users expect?
If your employer runs Citrix for remote access, sign-in pages may time out or refuse to load over the next few days as admins reboot gear and apply the update. That's the fix, not the attack. Use the official company portal, not any link that arrives by email claiming to help you reconnect to work systems. Phishing crews tend to ride the news cycle on outages like this one.
One reporter's read
The interesting detail isn't the CVSS number. A denial-of-service bug on an identity gateway being used in targeted attacks usually points to someone wanting a specific company's SSO dark for a window, not a smash-and-grab. Watch for a second-stage story in the next fortnight: whoever's knocking these boxes over is almost certainly doing it to cover something else.



