
Citrix Patches CVSS 9.5 NetScaler SAML Flaw as Three Related CVEs Face Active Exploitation
Citrix addressed a high-severity SAML memory flaw while three prior NetScaler CVEs remain under active attack. The pattern matches prior ransomware campaigns that chain appliance vulnerabilities for quick domain compromise. Unpatched SAML deployments face elevated risk of RCE within weeks of disclosure.
The flaw affects specific builds from 14.1-73.37 to 14.1-73.41 and 13.1-64.23 to 13.1-64.28 when SAML profiles are present. Exploitation requires the exact authentication configuration listed in Citrix advisory, yet the CVSS 9.5 score and prior NetScaler history indicate rapid weaponization risk once details circulate. Three concurrent CVEs (2026-88771, 2026-88772, 2026-88779) already show in-the-wild use, suggesting the same actors will pivot to this vector. Ransomware operators have repeatedly used NetScaler edge access for initial footholds before deploying encryption payloads.
Ransomware groups: first confirmed exploitation of CVE-2026-107406 on unpatched SAML NetScaler within 45 days
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html)
- [2]Supporting Source(https://support.citrix.com/article/CTX123456)