Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix released emergency updates for NetScaler ADC and Gateway fixing CVE-2026-88779, a SAML authentication flaw with a CVSS score of 8.7 that is being exploited in zero-day attacks causing denial-of-service. Researchers are investigating whether it can also lead to remote code execution, and CISA added it to its Known Exploited Vulnerabilities catalog.
- CVE-2026-88779: CVSS 8.7 memory buffer flaw in NetScaler SAML authentication
- Fixes in NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28, FIPS builds get 14.1-73.41 FIPS
- Attacks trigger nsaaad and Pitboss crashes, logs show shell commands downloading a payload
- CISA added the flaw to its KEV catalog, FCEB agencies must patch by October 7
Read next
Security