Threat Intelligence

Citrix Patches NetScaler Zero-Day Being Used in Targeted Attacks That Can Take Logins Offline

The Hacker News · 5 Oct 2026
Key Takeaway If your business runs its own NetScaler appliance, check whether it uses SAML authentication and apply Citrix's updates as soon as possible.

Citrix has released security updates for a high-severity flaw in NetScaler ADC and NetScaler Gateway that attackers have already exploited as a zero-day. The vulnerability, tracked as CVE-2026-88779, has a CVSS score of 8.7 out of 10. Citrix describes it as a memory overflow issue that can lead to denial-of-service under specific deployment conditions. It affects customer-managed NetScaler deployments running affected supported versions.

Exploitation requires the device to be configured as a SAML service provider or SAML identity provider. Citrix says it has seen targeted attacks on unmitigated deployments, and if the condition is triggered repeatedly, the service may remain unavailable. The company says the issue affects availability and it has not identified an impact on the integrity of customer data. Bishop Fox and watchTowr reported the flaw, and watchTowr said it reproduced the issue within hours of spotting NetScaler honeypot activity.

The patches follow Citrix's statement that it is tracking a separate, newly observed SAML authentication issue in deployments using Gateway or AAA functionality. They also follow reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunnelling tools on compromised systems. The US CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, with federal agencies required to patch by October 7, 2026.

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.