Citrix Patches Actively Exploited NetScaler SAML Zero-Day
Emergency updates address CVE-2026-88779; researchers probing remote code execution potential

Key Takeaways
- Citrix has released emergency patches for CVE-2026-88779, a zero-day denial-of-service vulnerability in NetScaler SAML functionality.
- The vulnerability is actively exploited in the wild prior to patching.
- Researchers are investigating whether the flaw can be leveraged for remote code execution beyond denial-of-service.
- NetScaler appliances with SAML enabled and exposed to the internet are at risk.
Related Security News

DIVD Reports Network Breach via Zammad Zero-Day Chain
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that its network was compromised through the exploitation of a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attack leveraged the vulnerabilities to facilitate unauthorized access, with reports indicating an AI-driven component to the breach. Both organizations are working on mitigations, and users are advised to apply updates as they become available.

Fortinet Warns of Actively Exploited Zero-Day in FortiMail Email Appliance
Fortinet has confirmed that a critical vulnerability in its FortiMail email security appliance is being exploited in the wild as a zero-day. The flaw, tracked as CVE-2026-104286, allows attackers to execute unauthorized code or commands on affected devices. The company has released security updates and urges customers to apply the latest firmware versions immediately to mitigate the risk.



