Citrix has shipped emergency updates for a NetScaler vulnerability that attackers have already exploited in the wild. The flaw, tracked as CVE-2026-88779, is described as a denial-of-service issue in NetScaler SAML, and Citrix is urging administrators to apply the patches immediately.

According to the advisory, the vulnerability has been used in zero-day attacks. Researchers are still investigating whether the bug can be escalated to remote code execution, which would significantly raise the severity of the threat.

With only one source available, there are no differing accounts to compare. The key takeaway is that organisations running affected NetScaler deployments should treat this as an active threat and update as soon as possible.