hacker-news · Crawled Oct 5, 2026

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Read original article ↗

AI Summary

A high-severity zero-day vulnerability, CVE-2026-88779, in Citrix NetScaler ADC and NetScaler Gateway is being actively exploited in targeted attacks to cause denial-of-service conditions on SAML-enabled deployments. The flaw is a memory overflow issue that can be triggered when the appliance is configured as a SAML service provider or identity provider. Citrix has released patches for affected versions, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7, 2026. No data integrity impact has been observed, but repeated exploitation can render services unavailable.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.