ALEXKRI.NET
Resume Contact
← Back

Citrix patches NetScaler SAML zero-day exploited in attacks

Patching last week’s NetScaler zero-days bought you about four days. CVE-2026-88779 (CVSS 8.7) is a memory buffer flaw in SAML SP/IdP configs, and appliances already sitting on 14.1-73.37 are getting hit, with shell commands stuffed into the username field. Fixed in 14.1-73.41 and 13.1-64.28, and CISA’s federal deadline is October 7. If SAML auth is on your Gateway, this is tonight.

Read the source ↗