Home / Oct 06, 2026 / Story
0
#2 The Hacker News general October 05, 2026 at 06:40 UTC

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

By [email protected] (The Hacker News)

AI Summary

Citrix patched CVE-2026-88779 (CVSS 8.7), a memory overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway that enables denial-of-service against SAML-based authentication deployments, with confirmed active exploitation in targeted attacks. The flaw emerged days after two other NetScaler zero-days were patched, suggesting attackers are actively researching the codebase for adjacent weaknesses. Organizations using SAML-authenticated NetScaler deployments are at particular risk and should apply the out-of-band patch immediately.

Relevance score: 87.0/100

# More from October 06