Citrix patches NetScaler SAML flaw used in zero-day attacks
The updates close a high-severity NetScaler bug that attackers were already using, forcing affected agencies and users to move quickly.
Citrix has issued emergency NetScaler updates for CVE-2026-88779, a memory-buffer bug in ADC and Gateway appliances tied to SAML authentication that was already being used in zero-day attacks. The vendor says the issue mainly causes denial of service, with a CVSS score of 8.7, and recommends moving to NetScaler ADC and NetScaler Gateway 14.1-73.41 or 13.1-64.28, with separate FIPS builds for affected customers. Security researchers and administrators are also seeing crash patterns and payload downloads on patched systems, so they are checking whether the flaw can do more than knock services offline. Citrix said the affected configs involve either a SAML SP or SAML IdP setup, and CISA added the bug to its Known Exploited Vulnerabilities catalog with a mitigation deadline of October 7 for FCEB agencies.
Why it matters
Organizations running NetScaler ADC or Gateway with SAML setups now have a patched path away from a flaw Citrix says was already exploited and linked to denial of service. The CISA deadline raises pressure on federal agencies to apply the fix by October 7, while Citrix’s affected versions define which environments need immediate attention. That narrows the response to patching or risk exposure, rather than waiting for broader confirmation of impact.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer