bleeping-computer · Crawled Oct 5, 2026

Citrix patches NetScaler SAML zero-day exploited in attacks

1 IoCs
Read original article ↗

AI Summary

Citrix has released emergency patches for a zero-day vulnerability, CVE-2026-88779, affecting NetScaler ADC and NetScaler Gateway appliances with SAML authentication enabled. The flaw, which stems from a memory buffer issue, has been exploited in active attacks to cause denial-of-service conditions, with evidence suggesting potential for remote code execution. Researchers and administrators have observed malicious activity, including shell command injection in authentication attempts and crashes of the nsaaad and Pitboss processes. A specific IP address, 213.209.159.55, has been linked to payload delivery, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
IP 213[.]209[.]159[.]55 Details →