Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix patches NetScaler SAML zero-day exploited in attacks

By Lawrence Abrams
Publication Date: 2026-10-04 21:58:00

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.

The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality.

The Citrix security advisory says the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial-of-service conditions.

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix said in a related blog post published today.

“If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of…