← All articles

Citrix patches third exploited NetScaler zero-day causing denial of service in SAML deployments

Citrix released updates for a high-severity NetScaler flaw, CVE-2026-88779, rated 8.7, that has been exploited in targeted zero-day attacks. It is a memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service under specific deployment conditions. Exploitation requires the appliance to be configured as a SAML service provider or SAML identity provider, which customers can confirm by checking their configuration for samlAction or samlIdPProfile entries. Fixed releases include 14.1-73.41 and later, 13.1-64.28 and later, and corresponding FIPS builds. This is the third exploited NetScaler zero-day disclosed in roughly two weeks, after the two remote code execution flaws Citrix confirmed in late September.

Check
Check NetScaler configurations for SAML service provider or identity provider entries, and upgrade affected ADC and Gateway deployments to the fixed releases now.
Affected
NetScaler ADC or Gateway configured as a SAML service provider or identity provider can be driven to denial of service by the memory overflow flaw.
Fix
Apply the fixed NetScaler releases, review SAML configuration exposure, and keep monitoring given repeated exploited zero-days against these appliances.