Wire · regulatory
Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 5 October 2026 · Fusion42 review
Citrix has issued urgent security updates for a critical zero-day vulnerability (CVE-2026-88779) in NetScaler ADC and Gateway appliances configured as SAML providers, which is actively exploited to cause denial of service. The vulnerability allows remote attackers to disrupt service availability without authentication, making prompt patching essential for affected customer-managed systems.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 3 sources have reported it between 5 Oct 2026 and 9 Oct 2026.
◆ ◆ The Wire takeaway
You must immediately audit your NetScaler appliances for vulnerable builds and SAML configuration, then apply Citrix’s latest patch to avoid active denial-of-service attacks. Delay raises risk of service disruption as attackers exploit the flaw without needing credentials or user interaction.
◆ Coverage
3 sources · first reported 5 Oct 2026 · latest 9 Oct 2026
◆ Related on Wire
◆ Topics