{
  "slug": "2026-10-05",
  "date": "2026-10-05",
  "updated": "2026-10-05",
  "title": "Use Citrix NetScaler with SAML login? Patch it now",
  "intro": "This week's top item: if your business uses Citrix NetScaler ADC or Gateway set up for SAML single sign-on, criminals are already exploiting a flaw in it to knock the login system offline. It's a different flaw to the one covered in our 28 September briefing, so patching that one doesn't cover this.",
  "quietWeek": false,
  "items": [
    {
      "id": "citrix-netscaler-saml-dos-oct2026",
      "rank": 1,
      "published": "2026-10-04",
      "title": "Use Citrix NetScaler with SAML login? Patch it now",
      "summary": "Citrix has confirmed criminals are already using a flaw in NetScaler ADC and NetScaler Gateway to crash the SAML (Security Assertion Markup Language) single sign-on feature many businesses use to let staff log in to multiple apps with one company account. The US Cybersecurity and Infrastructure Security Agency added it to its must-patch list on 4 October 2026 with an unusually tight three-day deadline for government agencies, a sign of how seriously it's being taken. The flaw only affects NetScaler devices specifically set up for SAML login, either as the identity provider or the service provider; other NetScaler setups are not affected by this particular issue.",
      "whoItAffects": "Businesses using Citrix NetScaler ADC or NetScaler Gateway specifically configured for SAML single sign-on. This is a different, newer flaw to the one in our 28 September briefing, so having patched that one doesn't cover this. If your NetScaler isn't set up for SAML login, or you don't run NetScaler at all, this one doesn't apply to you.",
      "action": "Ask your IT provider: \"Is our Citrix NetScaler set up for SAML login, and has it been updated to 14.1-73.41, 13.1-64.28, or later?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": ["CVE-2026-88779"],
      "cwes": ["CWE-119"],
      "links": [
        {
          "label": "CISA Known Exploited Vulnerabilities Catalog",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-88779"
        },
        {
          "label": "Citrix security bulletin CTX697174",
          "url": "https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html"
        }
      ]
    }
  ]
}
