Citrix Rolls Out Critical Patch for Actively Exploited NetScaler SAML Zero‑Day
Citrix Systems said today it is issuing emergency security updates to fix a newly revealed zero‑day flaw in its NetScaler ADC and NetScaler Gateway devices.
Identified as CVE‑2026‑88779, the defect lives in the SAML authentication component and can be activated by specially crafted requests, causing denial‑of‑service on the impacted units. Researchers have verified that attackers are already leveraging the vulnerability in real‑world scenarios, which spurred the swift action.
NetScaler devices are commonly used as load balancers, reverse proxies and secure gateways for enterprise web apps, and a large number of firms depend on their SAML capability for single‑sign‑on with identity providers. Since the bug exists in customer‑controlled deployments, systems that stay unpatched stay vulnerable to disruption and may be used as footholds for wider network breaches.
In its emergency advisory, Citrix urges administrators to install the freshly released firmware updates immediately. The company also suggests interim mitigations, like turning off SAML authentication on the affected units or limiting access to the vulnerable endpoints until the patches are applied.
Analysts point out that the swift abuse of a SAML‑related bug highlights how attackers are increasingly targeting identity‑focused components. Firms that have delayed regular patching are being reminded of the operational danger presented by unresolved flaws in essential infrastructure.
Going forward, Citrix commits to closely tracking the issue and issuing further guidance as new details emerge. Security teams should examine logs for irregular SAML traffic and work with incident‑response groups to contain any active attacks.
Comments (0)
Be the first to comment.
Join the discussion