Citrix patches NetScaler SAML zero-day exploited in attacks
Key Points:
- Citrix has released emergency updates to address a zero-day denial-of-service vulnerability (CVE-2026-88779) in NetScaler ADC and Gateway appliances using SAML authentication, which has been actively exploited in targeted attacks.
- The flaw, with a CVSS score of 8.7, causes service disruptions by triggering repeated crashes, and while Citrix states it impacts service availability without compromising data integrity, researchers suspect it may also allow remote code execution.
- Multiple NetScaler administrators reported unexpected reboots and crash patterns linked to crafted authentication requests, suggesting attempts to exploit the vulnerability for executing malicious payloads, though successful execution has not been fully confirmed.
- Citrix advises all affected customers, including those who recently updated for other NetScaler vulnerabilities, to apply the new patches immediately and use provided Global Deny Lists to block malicious IP addresses.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to mitigate the flaw by October 7, highlighting the urgency of patching vulnerable systems.