Security Briefing

Plain English cyber security for Australian small and medium business, every week: what happened, whether it affects you, and the one thing to do about it.

Use Citrix NetScaler with SAML login? Patch it now

Week of 5 to 11 October 2026

This week's top item: if your business uses Citrix NetScaler ADC or Gateway set up for SAML single sign-on, criminals are already exploiting a flaw in it to knock the login system offline. It's a different flaw to the one covered in our 28 September briefing, so patching that one doesn't cover this.

  1. 1

    Use Citrix NetScaler with SAML login? Patch it now

    Businesses using Citrix NetScaler ADC or NetScaler Gateway specifically configured for SAML single sign-on. This is a different, newer flaw to the one in our 28 September briefing, so having patched that one doesn't cover this. If your NetScaler isn't set up for SAML login, or you don't run NetScaler at all, this one doesn't apply to you.

    Citrix has confirmed criminals are already using a flaw in NetScaler ADC and NetScaler Gateway to crash the SAML (Security Assertion Markup Language) single sign-on feature many businesses use to let staff log in to multiple apps with one company account. The US Cybersecurity and Infrastructure Security Agency added it to its must-patch list on 4 October 2026 with an unusually tight three-day deadline for government agencies, a sign of how seriously it's being taken. The flaw only affects NetScaler devices specifically set up for SAML login, either as the identity provider or the service provider; other NetScaler setups are not affected by this particular issue.

    Do this

    Ask your IT provider: "Is our Citrix NetScaler set up for SAML login, and has it been updated to 14.1-73.41, 13.1-64.28, or later?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA Known Exploited Vulnerabilities Catalog ↗ · Citrix security bulletin CTX697174 ↗CVE-2026-88779 · CWE-119

Beyond this week's news

Reading about threats is step one. Knowing where you stand is step two.

See whether the security products you already pay for cover the basics (free, in about three minutes), or get a fixed-price, plain-English review of your whole setup.

Prefer LinkedIn? Follow TERESEC: the briefing lands there every Monday.

Latest ISM release: ISM September 2026: What Changed and What to Check →What the ISM is and how we assess it →

Past briefings