Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems. The vulnerability... Weiterlesen: Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
Intelligence View
⚡ tsecurity.de Intelligence
Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779,…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-88779
NVD: AnalyzedNVD 7.5 · HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD-Datenstand: 05.10.2026, 13:35 UTC
Ausnutzung beobachtet: Ja — aktiv Automatisierbar: Ja Technischer Impact: Teilweise
CISA KEV seit 04.10.2026 Frist: 07.10.2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
BSI-Warnung (Deutschland)CVE-2026-88779
Citrix NetScaler ADC und Gateway: Schwachstelle ermöglicht Denial of Service hoch04.10.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-88779
Exploitation: active (Aktiv ausgenutzt)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-04T19:34:09.964186Z · CISA Coordinator
Advisory Radar
Kritischer Zero-Day / Ohne Upstream-Patch
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencesupport.citrix.com