Citrix NetScaler SAML Zero-Day Exploited, Added to CISA KEV: What K-12 and Government IT Must Do Now
CISA KEV adds CVE-2026-88779, a Citrix NetScaler SAML zero-day exploited in attacks. Patch internet-facing ADC/Gateway, restrict SAML, and hunt logs.
- CISA added CVE-2026-88779, a Citrix NetScaler ADC/Gateway memory-buffer flaw, to KEV after evidence of active exploitation.
- Citrix released emergency updates for the NetScaler SAML zero-day; public-facing appliances are highest risk, with DoS confirmed and RCE under investigation.
- Schools and government agencies using NetScaler for remote access or SSO should patch, restrict management/SAML exposure, and hunt logs immediately.
What to do now
- Inventory all NetScaler ADC and Gateway appliances, note versions and internet exposure; apply Citrix emergency update for CVE-2026-88779 to internet-facing systems first.
- If patching is delayed, disable or tightly restrict SAML endpoints and remote access; limit management interface to trusted admin IPs and enforce MFA.
- Review NetScaler, SAML, and authentication logs for anomalous assertions, auth failures, unexpected outbound connections, config changes, or process/file anomalies; preserve evidence.
- Segment NetScaler from critical internal networks, rotate credentials/secrets for SSO accounts, and enforce least privilege.
- Track CISA KEV/BOD timelines and Citrix advisories; if compromise suspected, isolate, report to incident response and CISA, and prepare identity outage/RCE playbook.
Related items
- Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
- Citrix patches NetScaler SAML zero-day exploited in attacks
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
- Citrix NetScaler: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
- CISA Adds One Known Exploited Vulnerability to Catalog