Citrix patches NetScaler SAML zero-day exploited in attacks

Executive Summary

Citrix released emergency updates for a new NetScaler denial‑of‑service vulnerability (CVE-2026-88779) that has been exploited in zero‑day attacks. Researchers are investigating whether the flaw can also be used for remote code execution. The patch addresses the SAML authentication issue that allowed attackers to crash NetScaler appliances.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-10-04T21:58:01+00:00 - Category: threat-intel

Original Description: Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

"If we are facing in the right direction, all we have to do is keep on walking."

— Unknown
Source: Bleeping Computer