Citrix urges NetScaler users to patch exploited SAML flaw
Attackers are exploiting a newly reported flaw in Citrix NetScaler appliances, prompting the company to release a fix and US authorities to order federal agencies to patch it. The bug can disrupt access to services that rely on affected appliances for authentication.
Tracked as CVE-2026-88779, the memory overflow affects NetScaler ADC and Gateway systems configured for SAML single sign-on. Citrix confirmed targeted attacks and advised customers to install updated versions; CISA set a Wednesday deadline for federal agencies. Researchers say a single specially crafted request can crash an appliance, and recommend prioritising systems with SAML enabled.
- Attackers are exploiting a new NetScaler flaw.
- The bug can crash SAML-enabled appliances.
- CISA ordered federal agencies to patch by Wednesday.
New here? Start with this
Citrix NetScaler is computer equipment used by organisations worldwide to control access to their services and systems. It manages employee logins through a standard authentication system called SAML single sign-on. A security flaw has been discovered that attackers can exploit to disrupt this, preventing people from accessing the services they depend on.
The flaw causes the equipment to crash when an attacker sends it a specially crafted request. Citrix has confirmed that hackers are already attempting to exploit this weakness against its customers. The problem affects both NetScaler ADC and Gateway systems, particularly those configured for SAML authentication.
In response, Citrix has released a software update to fix the flaw. The US government's cybersecurity agency has ordered all federal agencies to install the patch by Wednesday, reflecting how serious the vulnerability is considered. Organisations using these systems are being urged to prioritise patching, particularly those using SAML for employee authentication.
Read the full article at the source →
Originally published by The Register as “Citrix NetScaler security snafus get even worse amid more 0-day reports”.