New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Summary

Citrix has issued security updates for a critical zero-day vulnerability, CVE-2026-88779, found in its NetScaler ADC and NetScaler Gateway products. This flaw has already been actively exploited in targeted attacks and can be used to take SAML deployments offline.

IFF Assessment

FOE

This vulnerability allows for targeted attacks to disrupt critical services, representing a significant threat to defenders.

Severity

8.7 High

The vulnerability has a high CVSS score of 8.7, indicating a significant security risk. The memory overflow flaw allows for targeted attacks that can disrupt SAML deployments, impacting availability and potentially leading to denial of service.

CISA KEV: Listed as actively exploited. Federal patch due: October 07, 2026. Known ransomware use: Unknown.

Defender Context

Organizations using Citrix NetScaler ADC or Gateway should prioritize patching this vulnerability immediately, as it is being actively exploited in the wild. Defenders need to be vigilant for indicators of compromise related to targeted attacks on these systems and ensure their SAML authentication infrastructure is resilient.

Read Full Story →