Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Reform internal inquiry says party did not break law over donations sting

    October 7, 2026

    Google now lets you make games with AI

    October 7, 2026

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Reform internal inquiry says party did not break law over donations sting
    • Google now lets you make games with AI
    • SonicWall warns of max severity SSRF flaw in SMA1000 gateways
    • Polymarket’s Shayne Coplan Calls Chasing 100x Tokens ‘Irrational Exuberance’
    • Nobel Prize in Chemistry awarded to Kagan and Soai
    • $533 million lands on Arabian Drilling’s backlog for rig quartet deal
    • The Next Era of Reform Must Be About Capability by Pepukaye Bardouille
    • Israeli papers commemorate October 7 attacks, three years on – Press Review
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 05, 2026Zero-Day / Vulnerability

    Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks.

    The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.

    “CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” Citrix said. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”

    For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following –

    • SAML SP – add authentication samlAction
    • SAML IdP – add authentication samlIdPProfile

    The issue has been addressed in the following versions –

    • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
    • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
    • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
    • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

    Citrix’s Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. In a post shared on X, watchTowr said it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity.

    Cybersecurity

    “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service,” the company acknowledged. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

    The patches come after Citrix said it’s tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it’s related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.

    The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.

    attacks deployments Exploited Knock NetScaler offline SAML targeted ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    Israeli papers commemorate October 7 attacks, three years on – Press Review

    Zelensky condemns ‘vile’ large-scale Russian attacks that killed 15

    Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

    Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

    100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Reform internal inquiry says party did not break law over donations sting

    October 7, 2026

    Google now lets you make games with AI

    October 7, 2026

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    October 7, 2026

    Polymarket’s Shayne Coplan Calls Chasing 100x Tokens ‘Irrational Exuberance’

    October 7, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Reform internal inquiry says party did not break law over donations sting

    October 7, 2026

    Google now lets you make games with AI

    October 7, 2026

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.