Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline




A critical zero-day vulnerability in Citrix's NetScaler ADC and Citrix NetScaler Gateway has been exploited by targeted attackers, resulting in the disruption of SAML deployments. In this article, we will explore the details of this vulnerability, its implications, and the necessary steps that organizations can take to protect themselves.



  • Zero-day vulnerability in Citrix's NetScaler ADC and Citrix NetScaler Gateway has been exploited by targeted attackers, resulting in disruption of SAML deployments.
  • Citrix has released security updates for a high-severity security flaw with a critical severity score of 8.7 out of 10.0.
  • The vulnerability affects customer-managed NetScaler deployments running certain supported versions configured as SAML service providers or identity providers.
  • Organizations can review their configuration to determine if their deployment meets the precondition.
  • Citrix has released patches for the affected versions, including NetScaler ADC and Gateway 14.1-73.41 and later releases.
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.
  • Organizations must take immediate action to protect themselves, including reviewing their deployments, applying patches, and ensuring proper configuration.



  • The cybersecurity landscape continues to evolve at an unprecedented rate, with new threats emerging on a daily basis. In a recent development, a zero-day vulnerability in Citrix's NetScaler ADC and Citrix NetScaler Gateway has been exploited by targeted attackers, resulting in the disruption of SAML deployments. In this article, we will delve into the details of this vulnerability, its implications, and the necessary steps that organizations can take to protect themselves.

    Citrix has recently released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway, which has been tracked as CVE-2026-88779. This vulnerability carries a critical severity score of 8.7 out of 10.0, highlighting its potential impact on the security of affected deployments. According to Citrix, the vulnerability is a memory overflow vulnerability that can lead to denial-of-service under specific deployment conditions. This means that even if the deployment is properly configured, the vulnerability can still be exploited to disrupt the service.

    The issue at hand affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met. In other words, the vulnerability is not present in all deployments, but rather those that are configured as SAML service providers (SP) or SAML identity providers (IdP). This is crucial information for organizations, as it highlights the importance of proper configuration and management of their SAML deployments.

    To determine if their NetScaler deployment meets the precondition, customers can review their configuration for entries matching the following:

    - SAML SP - add authentication samlAction
    - SAML IdP - add authentication samlIdPProfile

    Fortunately, Citrix has released patches for the affected versions, which include:

    - NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
    - NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
    - NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
    - NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

    Citrix's Cloud Software Group has credited Bishop Fox and watchTowr for reporting the vulnerability, while watchTowr has shared that it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity. Citrix has acknowledged that targeted attacks on unmitigated NetScaler deployments have led to denial-of-service, and that if the condition is triggered repeatedly, the service may remain unavailable.

    The development also follows reports of active exploitation of other CVEs, including CVE-2026-88771 and CVE-2026-88772, to plant web shells and tunneling tools on compromised systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.

    In light of this vulnerability, it is essential for organizations to take immediate action to protect themselves. This includes reviewing their SAML deployments, applying the necessary patches, and ensuring that their configuration is properly managed.

    The implications of this vulnerability are significant, as it highlights the importance of regular security updates and proper configuration of SAML deployments. Organizations that fail to take these steps risk falling victim to targeted attacks and disruption of their services.

    Furthermore, this vulnerability serves as a reminder of the importance of vigilance in the cybersecurity landscape. As new threats emerge, it is crucial for organizations to stay informed and take proactive steps to protect themselves.

    In conclusion, the recent exploitation of a zero-day vulnerability in Citrix's NetScaler ADC and Citrix NetScaler Gateway has highlighted the importance of regular security updates and proper configuration of SAML deployments. Organizations must take immediate action to protect themselves, including reviewing their deployments, applying patches, and ensuring proper configuration.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-NetScaler-Zero-Day-Exploited-in-Targeted-Attacks-Can-Knock-SAML-Deployments-Offline-ehn.shtml

  • https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html

  • https://cybersecuritynews.com/citrix-netscaler-saml-0-day-vulnerability/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-88771

  • https://www.cvedetails.com/cve/CVE-2026-88771/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-88772

  • https://www.cvedetails.com/cve/CVE-2026-88772/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-88779

  • https://www.cvedetails.com/cve/CVE-2026-88779/


  • Published: Mon Oct 5 03:38:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us