Hackers are actively exploiting a new zero-day vulnerability in Citrix NetScaler. If your perimeter gateway was hoping for a quiet afternoon, I've got some bad news.
It's tracked as CVE-2026-88779. This is a critical, unauthenticated memory overflow flaw affecting both NetScaler ADC and Gateway appliances. In plain English, an attacker with zero valid credentials can send crafted network packets directly to your gateway. That gives them unauthenticated remote code execution before your morning coffee even kicks in. It turns out letting boundary checks slide on edge routing devices is still a favorite tactic among threat actors—yeah, big surprise there.
Here's what every security operations team and system administrator needs to know right now.
First, how the exploit works. Under the hood, this buffer overflow lives in the packet processing handler for authentication endpoints. An attacker delivers an oversized, malformed HTTP header payload to the appliance. The input validation routines fail to calculate buffer boundaries properly, so the payload spills over and corrupts memory on the heap immediately. In under thirty seconds, the execution flow is hijacked. That allows the attacker to run arbitrary commands with full administrative privileges.
Second, the indicators of compromise. Spotting this in production traffic is tricky because standard traffic inspection often overlooks raw memory corruption. Check your NetScaler crash logs right away for core dumps and recurring segmentation faults in the primary packet engine process. On the network side, inspect your firewall telemetry for unusual outbound connections originating directly from your NetScaler management interfaces to unknown external IP addresses. Watch closely for non-standard TLS ports or atypical SSH channels. If your gateway is initiating outbound connections to unfamiliar infrastructure, you're already dealing with an active breach.
Third, immediate mitigation steps while you prepare to deploy the emergency security patch. If you can't reboot and patch your appliances this exact second, isolate your management interfaces behind trusted, restricted subnets right away. Make sure access to management ports is completely blocked from the public internet. Next, update your web application firewall rules to inspect and drop malformed HTTP request headers exceeding standard size limits on public-facing virtual servers. Keep in mind that WAF signatures are only a temporary band-aid against an evolving memory overflow exploit.
Audit your appliances, pull those management ports off the public web, and schedule your emergency patch rollout across all ADC and Gateway instances immediately. Subscribe for continuous security updates and threat intelligence breakdowns, and let's make sure the attackers have a significantly worse day than your incident response team.