Citrix NetScaler SAML Zero-Day Exploited, Added to CISA KEV: What K-12 and Government IT Must Do Now

CISA KEV adds CVE-2026-88779, a Citrix NetScaler SAML zero-day exploited in attacks. Patch internet-facing ADC/Gateway, restrict SAML, and hunt logs.

  • CISA added CVE-2026-88779, a Citrix NetScaler ADC/Gateway memory-buffer flaw, to KEV after evidence of active exploitation.
  • Citrix released emergency updates for the NetScaler SAML zero-day; public-facing appliances are highest risk, with DoS confirmed and RCE under investigation.
  • Schools and government agencies using NetScaler for remote access or SSO should patch, restrict management/SAML exposure, and hunt logs immediately.

What to do now

  1. Inventory all NetScaler ADC and Gateway appliances, note versions and internet exposure; apply Citrix emergency update for CVE-2026-88779 to internet-facing systems first.
  2. If patching is delayed, disable or tightly restrict SAML endpoints and remote access; limit management interface to trusted admin IPs and enforce MFA.
  3. Review NetScaler, SAML, and authentication logs for anomalous assertions, auth failures, unexpected outbound connections, config changes, or process/file anomalies; preserve evidence.
  4. Segment NetScaler from critical internal networks, rotate credentials/secrets for SSO accounts, and enforce least privilege.
  5. Track CISA KEV/BOD timelines and Citrix advisories; if compromise suspected, isolate, report to incident response and CISA, and prepare identity outage/RCE playbook.

Related items