---
title: Citrix Netscaler Zero-Day Exploit Causes Crashes and Code Execution
url: https://www.dataloco.com/en/citrix-netscaler-zero-day-exploit-causes-crashes-and-code-execution
published: 2026-10-05T16:22:18+00:00
language: en
section: Security
source: https://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag
organizations: Citrix, Netscaler, CISA
publisher: Dataloco
---

# Citrix Netscaler Zero-Day Exploit Causes Crashes and Code Execution

A newly discovered exploit targeting Citrix Netscaler devices has triggered widespread crashes and unauthorized code execution on systems with SAML features enabled. The vulnerability, identified as CVE-2026-88779, affects administrators who have not yet applied the latest patches. Security researcher Kevin Beaumont reported that the exploit bypasses previously patched flaws, including CVE-2026-88771 and CVE-2026-88772, and leverages a buffer overflow in configurations using add authentication samlAction or add authentication samlIdPProfile.

WatchTowr Labs confirmed successful reproduction of the attack, which allows malware injection and network breaches through mass SAML request flooding. CISA added the flaw to its known exploited vulnerabilities list on October 4, 2026, urging immediate remediation. Citrix released patches on October 3, 2026, but did not provide mitigation guidance, directing users to contact support.

The advisory specifies that updates must be applied to versions addressing the critical vulnerability with a CVSS4 score of 8.7. Administrators are advised to upgrade without delay to prevent exploitation.

## This story in other languages

- [Polski](https://www.dataloco.com/pl/luka-typu-zero-day-w-urzadzeniach-citrix-netscaler-powoduje-awarie-i-wykonanie-kodu)
