← All security news

Citrix NetScaler SAML Zero-Day Exploited — Here's What to Patch

A login gateway icon cracking under a memory-overflow warning, with an update-now badge

Citrix has released emergency patches for CVE-2026-88779, a memory-overflow flaw in how NetScaler ADC and NetScaler Gateway handle SAML single sign-on, after confirming it is already being used in live attacks. Administrators first noticed unexplained appliance reboots; researchers who dug into the crashes found attackers sending authentication requests with shell commands hidden inside the username field, attempting to download and run malicious payloads. Citrix says the confirmed impact so far is denial of service — appliances crashing and restarting — though the bug's root cause leaves room for worse, which is why both Citrix and CISA are treating it as urgent.

The flaw only affects NetScaler instances configured for SAML authentication, as either a service provider or identity provider — the setup many businesses use to let employees log into a VPN or internal apps with one company-wide login. Fixed versions are 14.1-73.41 and 13.1-64.28 (plus matching FIPS and NDcPP builds), released in an out-of-cycle update over the weekend. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on 4 October, its standard signal that an unpatched flaw is actively being used against real targets, not just a theoretical risk. This is a different bug from the two NetScaler zero-days Citrix patched in late September — the third NetScaler emergency patch inside two weeks.

What this means for your business

If your business runs a NetScaler ADC or Gateway appliance — commonly used for VPN access or single sign-on to internal systems — ask whoever manages it this week whether SAML authentication is configured, and if so, whether the appliance has been updated to 14.1-73.41 or 13.1-64.28. This is usually IT staff or an outsourced network provider, not your website developer, so it's worth a direct message rather than assuming it's covered by routine maintenance. Citrix also offers a temporary deny-list mitigation for appliances that can't be patched immediately; ask your provider whether that's been applied in the meantime.

More broadly, login and remote-access gateways are a favourite target precisely because they sit on the edge of your network with high-value access behind them. If your business has any appliance in this category — VPN concentrator, SSO gateway, remote-access portal — it's worth confirming there's a routine for checking vendor security bulletins and applying patches promptly, rather than waiting for the next headline to ask.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, CISA, Citrix security bulletin CTX697174