Security News

Citrix NetScaler Hit by Another Actively Exploited Flaw Before a Patch Was Ready

The Register · 6 Oct 2026
Key Takeaway If your business runs NetScaler ADC or Gateway with SAML single sign-on, apply Citrix's updated versions immediately and check with your IT provider that earlier fixes are also in place.

Attackers have found and exploited another previously unknown flaw in Citrix NetScaler appliances. The bug, tracked as CVE-2026-88779, is a memory overflow issue that can cause denial of service. It only affects NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, which are used for single sign-on authentication.

Citrix confirmed late on a Friday that it was investigating a newly observed SAML-related issue. By Saturday night it had released a security advisory with patches and urged customers to install the updated versions as soon as possible. The company said it has seen targeted attacks on unmitigated deployments. It did not say how many instances were affected or what attackers do after exploiting the bug. On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation and ordered federal agencies to patch by Wednesday.

The flaw is not technically related to eight other vulnerabilities Citrix disclosed on September 27, weeks after attackers began abusing two of them (CVE-2026-88772 and CVE-2026-88771). However, researchers at watchTowr told The Register they suspect the new bug has been used to deliberately crash machines, which would make exploitation of CVE-2026-88771 faster.

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.