Particle.news

Citrix Issues Emergency Fix for Exploited NetScaler SAML Zero‑Day

CISA has ordered federal remediation by October 7, raising urgency across networks.

Overview

  • Citrix released emergency updates on Sunday to address CVE‑2026‑88779, a memory overflow in NetScaler ADC and Gateway that affects customer‑managed deployments using SAML authentication.
  • The flaw can crash appliances and cause repeated reboots when SAML is configured as a service provider or identity provider, and Citrix shipped Global Deny List signatures and an indicator script as interim protections.
  • Researchers and honeypot operators observed active exploitation that produced crash patterns, authentication requests containing shell commands in the username field, and at least one downloaded malware binary on a patched honeypot.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate by October 7, which makes rapid patching and forensic preservation mandatory for those networks.
  • Operators are urged to upgrade the specified NetScaler versions immediately, check logs and volatile memory for signs of compromise, preserve backups and evidence before remediation, and treat exposed appliances as potentially breached while investigators probe possible remote‑code execution.