New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
AI-summarised brief · reviewed before publication
Citrix issued patches for a high‑severity memory‑overflow flaw (CVE‑2026‑88779) in NetScaler ADC and Gateway that can trigger denial‑of‑service when the appliance is configured as a SAML service provider or identity provider. The vulnerability, rated 8.7/10, has been actively exploited in targeted attacks, with attackers using AI‑driven reconnaissance to identify vulnerable deployments. Citrix credited Bishop Fox and watchTowr for discovery, and the U.S. CISA has added the flaw to its Known Exploited Vulnerabilities list, mandating federal fixes by October 7, 2026.
💡 Why It Matters
- · The flaw exposes a critical attack vector that can cripple SAML‑based authentication, a cornerstone of enterprise single‑sign‑on.
- · Prompt patching is essential to prevent widespread service outages and protect sensitive identity data.