Citrix NetScaler SAML Zero-Day CVE-2026-88779 Exploited

Citrix NetScaler SAML Zero-Day CVE-2026-88779 Exploited

By eSecurityPlanet Staff
Publication Date: 2026-10-05 11:00:00

Citrix has released emergency updates for CVE-2026-88779, a high-severity NetScaler memory-overflow vulnerability that attackers exploited as a zero-day against SAML-enabled deployments.

The flaw can trigger denial-of-service conditions in affected customer-managed NetScaler ADC and NetScaler Gateway appliances. Citrix says repeated exploitation can leave the service unavailable, but its current analysis has not identified an impact on customer data integrity.

The Citrix security bulletin assigns CVE-2026-88779 a CVSS 4.0 score of 8.7. Citrix disclosed the vulnerability Oct. 3 and said it had observed targeted attacks against unmitigated deployments.

CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate it by Oct. 7.

CVE-2026-88779 targets SAML-enabled NetScaler deployments

Exposure depends on the appliance configuration.

Citrix says affected NetScaler ADC or NetScaler Gateway deployments must be configured as either a SAML…