Back to News
News · Cybersecurity

New NetScaler Zero-Day Can Knock SAML Deployments Offline

A high-severity Citrix flaw is being exploited in targeted attacks against unmitigated appliances.

Source: The Hacker News · October 2026

The Hacker News reports that Citrix has patched a high-severity zero-day, tracked as CVE-2026-88779 with a CVSS score of 8.7, in NetScaler ADC and NetScaler Gateway. The flaw is a memory overflow that can cause denial-of-service when the appliance is configured as a SAML service provider or identity provider, and Citrix says it has observed targeted attacks against unmitigated deployments, with repeated triggering able to keep the service unavailable.

Citrix credits Bishop Fox and watchTowr for reporting the issue and has shipped fixes in NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28, along with the relevant FIPS releases. CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, giving federal agencies until October 7, 2026 to apply the patch.

Why it matters: NetScaler sits at the authentication edge for many enterprise networks, so an outage there can take down SAML-based single sign-on across the business. Patch promptly, review whether your deployment runs as a SAML SP or IdP, and confirm the fix is applied ahead of any compliance deadline.