Live Feeds
● LIVE Updated 41m ago · 14 sources tracked

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix released emergency security updates for a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway deployments. Tracked as CVE-2026-88779 and carrying a CVSS score of 8.7 out of 10.0, the zero-day flaw has been actively exploited in targeted attacks. The issue can knock SAML deployments offline or trigger a denial-of-service condition when the appliance is configured as a SAML service provider or identity provider. Crucially, the latest wave of exploitation has impacted customer-managed appliances that were already fully patched against earlier zero-day vulnerabilities released just days prior.

🎙️

Listen to Live Briefing

Real-time synthesized voice briefing · Live Feeds Desk

⏱ ~3 min
Speed:
RSS Source map (14)
⚡ Key Developments & Real-Time Context
Text size:
  • ✓ Citrix released emergency updates for a new NetScaler vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks.
  • ✓ CVE-2026-88779 carries a CVSS score of 8.7 out of 10.0.
  • ✓ CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions.
  • ✓ For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider or a SAML identity provider.
🛡️ Source Corroboration: 14 independent reporting domains (100% confidence) ⏱ Read time: ~3 min

What changed

Citrix issued an emergency patch for a third zero-day vulnerability, CVE-2026-88779, which attackers used to target NetScaler appliances that were patched days earlier.

Live updates

  1. Citrix Patches NetScaler SAML Zero-Day Exploited in Attacks

    Citrix released emergency security updates for a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway deployments. Tracked as CVE-2026-88779 and carrying a CVSS score of 8.7 out of 10.0, the zero-day flaw has been actively exploited in targeted attacks. The issue can knock SAML deployments offline or trigger a denial-of-service condition when the appliance is configured as a SAML service provider or identity provider. Crucially, the latest wave of exploitation has impacted customer-managed appliances that were already fully patched against earlier zero-day vulnerabilities released just days prior.

    Why it matters

    This incident highlights the mounting difficulties organizations face when dealing with rapid, multi-stage zero-day patching cycles at the network edge. Having just closed tickets for two previously exploited flaws, administrators now must apply a third update for devices already rendered vulnerable under specific SAML configurations. The rapid succession of targeted attacks underscores the pressure on enterprise defenders maintaining customer-managed NetScaler appliances.

    What is confirmed

    • Citrix released emergency updates for a new NetScaler vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks.
    • CVE-2026-88779 carries a CVSS score of 8.7 out of 10.0.
    • CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions.
    • For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider or a SAML identity provider.
    • Fixed versions for CVE-2026-88771 and CVE-2026-88772 were released for NetScaler ADC and Gateway on September 27.

    Still unconfirmed

    • Administrators and security researchers are reporting massive spontaneous reboots of affected devices.

    What to watch next

    • Confirmation from security researchers or vendors on whether CVE-2026-88779 allows remote code execution beyond denial-of-service.
    • Reports of additional zero-day flaws emerging for customer-managed NetScaler deployments.
    Sources used for this update (16)
    1. BleepingComputer — Citrix patches NetScaler SAML zero-day exploited in attacks
    2. The Hacker News — New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
    3. Cybersecurity Dive — Mass exploitation of Citrix NetScaler: What we currently know
    4. unit42.paloaltonetworks.com — Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
    5. Dark Reading — Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
    6. SecurityWeek — Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
    7. thehackernews.com — ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
    8. note.com — NetScaler patched last week needs another update—Reading the facts on the third zero-day, CVE-2026-88779
    9. www.bleepingcomputer.com — Latest In-App Notification news
    10. note.com — 先週PatchしたNetScalerも再更新――3件目のZero-day CVE-2026-88779をFactで読む
    11. www.bleepingcomputer.com — Citrix patches NetScaler SAML zero-day exploited in attacks - BleepingComputer
    12. thehackernews.com — New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
    confidence 100%
📊

Community Sentiment: How do you assess this situation?

Voice your perspective · Real-time aggregated sentiment from the Live Feeds community