Active Exploitation Reported for Citrix NetScaler SAML Authentication Vulnerability

A newly discovered high-severity vulnerability in Citrix NetScaler ADC and Gateway appliances is being actively exploited by attackers targeting systems configured with SAML authentication. This flaw emerges shortly after Citrix patched two other critical vulnerabilities in the same product line. Organizations running affected NetScaler deployments face immediate risk and should prioritize applying security updates.
The vulnerability affects Citrix NetScaler appliances used for application delivery and remote access services. Organizations with SAML-based authentication systems face particular risk, as the flaw can be triggered remotely without requiring credentials or user action. The timing compounds the severity, as IT teams were already occupied addressing two earlier critical flaws in the same product line.
CISA has prioritized this threat for federal systems, establishing a remediation deadline of October 7, 2026. The memory overflow nature of the defect means repeated attacks could cumulatively degrade or disable affected services, potentially disrupting business continuity for organizations dependent on these appliances for secure remote access and internal application delivery.
Organizations relying on Citrix NetScaler infrastructure for remote work capabilities and network access could experience service disruptions if systems remain unpatched. The rapid succession of critical vulnerabilities may strain IT resources, particularly in smaller organizations with limited security staffing. Delayed remediation could leave sensitive applications and user authentication systems vulnerable to denial-of-service attacks, potentially affecting employee productivity and customer access to services.