Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks

Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks

By Guru Baran
Publication Date: 2026-10-05 01:49:00

Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems.

The vulnerability carries a CVSS v4.0 score of 8.7 and affects appliances configured as a SAML service provider or identity provider. Citrix describes it as a memory overflow, classified under CWE-119, where software fails to keep memory operations within the bounds of a buffer.

Citrix confirmed targeted attacks against unmitigated deployments. Repeated exploitation can keep affected services unavailable. The company said its analysis showed an impact on service availability but had not identified any impact on the integrity of customer data. That distinction matters: the confirmed vendor assessment is denial of service, not proven data theft.