Exploited NetScaler Zero-Day Disrupts SAML Services

Citrix has patched CVE-2026-88779, a high-severity NetScaler memory overflow vulnerability exploited in targeted zero-day attacks. The flaw can repeatedly crash NetScaler ADC and Gateway services configured as a SAML service provider or identity provider, potentially causing prolonged denial of service. Citrix has found no evidence of compromised customer data, but CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog. Organizations should install the latest 13.1 or 14.1 security release immediately, with US federal agencies required to patch by October 7, 2026.

Reference: thehackernews.com