โ Back to Feed
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
CVE-2026-88779
October 5, 2026 ยท The Hacker News ยท Severity: CRITICAL
This article reports a high-severity zero-day vulnerability in Citrix NetScaler ADC and Gateway that leads to denial-of-service under specific SAML configurations. Citrix has observed targeted attacks and released security updates for affected versions. Researchers have reproduced the flaw quickly after detecting honeypot activity. ๐ **Analyst Note:** The targeted nature of these attacks suggests threat actors are specifically seeking out SAML-configured NetScaler deployments. Administrators should immediately check their configurations and apply patches, as the DoS condition could disrupt critical authentication services.
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779 , carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said . "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following - SAML SP - add authentication samlAction SAML IdP - add authentication samlIdPProfile The issue has been addressed in the following versions - NetScaler ADCand NetScaler Gateway 14.1-73.41 and later releases NetScaler ADCand NetScaler Gateway 13.1-64.28 and later releases of 13.1 NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. In a post shared on X, watchTowr said it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity. "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service," the company acknowledged. "If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data." The patches come after Citrix said it's tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it's related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality. The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring federal agencies to apply the patches by October 7, 2026. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- Citrix NetScaler ADC and Gateway are affected by CVE-2026-88779, a memory overflow vulnerability that can cause denial-of-service when configured as a SAML provider.
- The vulnerability has been exploited in targeted zero-day attacks, and Citrix has released patches for multiple versions to mitigate the issue.
- Successful exploitation requires the NetScaler to be configured as a SAML service provider or identity provider, and repeated triggering can keep the service offline.