Monday , October 5 2026
Citrix

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this issue affects customer-managed NetScaler ADC and NetScaler Gateway devices and can cause service shutdowns, blocking access to services that rely on these systems.

The flaw has a CVSS v4.0 score of 8.7. It affects devices set up as a SAML service provider or identity provider. Citrix calls it a memory overflow. This falls under CWE-119, where software doesn’t manage memory operations within the limits of a buffer.

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

Citrix said there are attacks against systems that are not fixed. Ongoing exploitation can make services go down for a long time. The company found that service availability was affected but did not see any issues with customer data. This is important: the confirmed problem is denial of service, not data theft.

The CVSS vector shows that attackers can exploit the flaw through a network without needing passwords or user actions. The complexity is low, so devices with the needed SAML setup should receive urgent updates.

Investigators found requests to verify identity that had shell commands meant to download and run a program. These requests came before confirmed crashes, but the admin looking at them didn’t prove that the commands worked.

Security expert Kevin Beaumont reported a malware file running on a fixed honeypot. Meanwhile, watchTowr said they could recreate the issue. These findings worry about possible code running, but they are not the same as Citrix’s confirmed claim that this CVE is a denial-of-service problem.

Data breach protection Affected Versions and Configuration Checks

Citrix’s security notice names NetScaler ADC and Gateway versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28 as affected. NetScaler ADC FIPS versions before 14.1-73.41 FIPS are also at risk, along with NetScaler ADC FIPS and NDcPP versions before 13.1-37.282.

Secure private access hybrid setups with affected NetScaler instances need updates too. The bulletin is for customer-managed systems. Cloud Software Group takes care of updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Administrators can check the configuration for add authentication samlAction, which identifies a SAML service provider, or add authentication samlIdPProfile, which identifies a SAML identity provider. Either entry meets the stated configuration requirement. Finding it shows potential exposure on an affected build, not proof that attackers have compromised the appliance.

Customers must install 14.1-73.41 or newer on the 14.1 branch, or 13.1-64.28 or newer on the 13.1 branch. FIPS customers need 14.1-73.41 FIPS or newer. Also, 13.1 FIPS and NDcPP deployments need 13.1-37.282 or newer in their branches.

Organizations that updated their NetScaler security before need to upgrade again if they fit this vulnerability’s conditions. Citrix is giving out Global Deny Lists to block bad IP addresses, but still advises quick patching. The advisory thanks Bishop Fox and watchTowr for their help in protecting customers.

For security teams, the first job is to compare each appliance’s setup and SAML settings with the bulletin, then make the right update. Just recent patches are not enough: systems on old fixed builds can still be attacked because of this new SAML weakness.

Check Also

CISA

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw …