Citrix patches NetScaler SAML zero-day exploited in attacks
Executive Summary
Citrix released emergency updates for a new NetScaler denial‑of‑service vulnerability (CVE-2026-88779) that has been exploited in zero‑day attacks. Researchers are investigating whether the flaw can also be used for remote code execution. The patch addresses the SAML authentication issue that allowed attackers to crash NetScaler appliances.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-10-04T21:58:01+00:00 - Category: threat-intel
Original Description: Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
"If we are facing in the right direction, all we have to do is keep on walking."
— Unknown