Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix released emergency security updates for a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway deployments. Tracked as CVE-2026-88779 and carrying a CVSS score of 8.7 out of 10.0, the zero-day flaw has been actively exploited in targeted attacks. The issue can knock SAML deployments offline or trigger a denial-of-service condition when the appliance is configured as a SAML service provider or identity provider. Crucially, the latest wave of exploitation has impacted customer-managed appliances that were already fully patched against earlier zero-day vulnerabilities released just days prior.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Citrix released emergency updates for a new NetScaler vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks.
- ✓ CVE-2026-88779 carries a CVSS score of 8.7 out of 10.0.
- ✓ CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions.
- ✓ For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider or a SAML identity provider.
What changed
Citrix issued an emergency patch for a third zero-day vulnerability, CVE-2026-88779, which attackers used to target NetScaler appliances that were patched days earlier.
Live updates
-
Citrix Patches NetScaler SAML Zero-Day Exploited in Attacks
Citrix released emergency security updates for a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway deployments. Tracked as CVE-2026-88779 and carrying a CVSS score of 8.7 out of 10.0, the zero-day flaw has been actively exploited in targeted attacks. The issue can knock SAML deployments offline or trigger a denial-of-service condition when the appliance is configured as a SAML service provider or identity provider. Crucially, the latest wave of exploitation has impacted customer-managed appliances that were already fully patched against earlier zero-day vulnerabilities released just days prior.
Why it matters
This incident highlights the mounting difficulties organizations face when dealing with rapid, multi-stage zero-day patching cycles at the network edge. Having just closed tickets for two previously exploited flaws, administrators now must apply a third update for devices already rendered vulnerable under specific SAML configurations. The rapid succession of targeted attacks underscores the pressure on enterprise defenders maintaining customer-managed NetScaler appliances.
What is confirmed
- Citrix released emergency updates for a new NetScaler vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks.
- CVE-2026-88779 carries a CVSS score of 8.7 out of 10.0.
- CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions.
- For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider or a SAML identity provider.
- Fixed versions for CVE-2026-88771 and CVE-2026-88772 were released for NetScaler ADC and Gateway on September 27.
Still unconfirmed
- Administrators and security researchers are reporting massive spontaneous reboots of affected devices.
What to watch next
- Confirmation from security researchers or vendors on whether CVE-2026-88779 allows remote code execution beyond denial-of-service.
- Reports of additional zero-day flaws emerging for customer-managed NetScaler deployments.
confidence 100%Sources used for this update (16)
- BleepingComputer — Citrix patches NetScaler SAML zero-day exploited in attacks
- The Hacker News — New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- Cybersecurity Dive — Mass exploitation of Citrix NetScaler: What we currently know
- unit42.paloaltonetworks.com — Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
- Dark Reading — Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
- SecurityWeek — Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
- thehackernews.com — ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
- note.com — NetScaler patched last week needs another update—Reading the facts on the third zero-day, CVE-2026-88779
- www.bleepingcomputer.com — Latest In-App Notification news
- note.com — 先週PatchしたNetScalerも再更新――3件目のZero-day CVE-2026-88779をFactで読む
- www.bleepingcomputer.com — Citrix patches NetScaler SAML zero-day exploited in attacks - BleepingComputer
- thehackernews.com — New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community