New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- ID
- 31827
- Status
- summarized
- Published
- 05 Oct 2026, 2:40 PM
- Fetched
- 06 Oct 2026, 2:50 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 06 Oct 2026, 2:51 AM
- Tags
- Audience
- developerssaas_founders
What happened
Citrix patched CVE-2026-88779, a CVSS 8.7 memory overflow in NetScaler ADC and NetScaler Gateway that has been exploited in targeted zero-day attacks and can cause denial-of-service when the appliance is configured as a SAML service provider or identity provider. Patches are in NetScaler ADC/Gateway 14.1-73.41+, 13.1-64.28+, 14.1-FIPS 14.1-73.41+, and 13.1-FIPS/13.1-NDcPP 13.1-37.282+. Citrix says it has not identified impact on customer data integrity, but repeated triggering may leave the service unavailable.
Why it matters
Only teams self-managing NetScaler ADC/Gateway with SAML SP or IdP config need to act: check for 'add authentication samlAction' or 'add authentication samlIdPProfile', then upgrade to the listed versions; everyone else can treat this as low priority. The text provides no Malaysian or Southeast Asian-specific impact, so local relevance is limited to organizations running that stack.
Discussion angle
If your product or employer uses SAML behind a self-managed NetScaler, what is your patch and failover plan for an authentication outage caused by repeated DoS attempts, especially when the vendor says data integrity is not affected?