New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

A devastating new zero-day vulnerability in NetScaler has been exploited in targeted attacks, rendering SAML deployments vulnerable to downtime and data breaches. The attackers are targeting organizations that rely on Single Sign-On (SSO) and federated identity management solutions, leveraging a previously unknown weakness in the NetScaler product.

NetScaler is a popular software load balancer and application delivery controller developed by Citrix, widely used in enterprise environments for securing and optimizing web applications. SAML, or Security Assertion Markup Language, is an industry standard protocol for authentication and authorization between different systems and domains. When properly configured, SAML enables seamless user access to multiple applications without requiring separate login credentials.

Attackers are exploiting the vulnerability by targeting SAML deployments that use NetScaler as their load balancer. Once compromised, the attackers can manipulate SAML assertions, effectively disabling SSO capabilities and forcing users to re-authenticate or lock them out of the system altogether. This not only disrupts business operations but also opens up vulnerabilities for attackers to breach sensitive data.

The exploitation of this zero-day vulnerability is particularly concerning due to its potential to create a “choke point” in an organization’s security posture. By targeting SAML deployments, attackers can compromise an entire ecosystem of interconnected systems and applications, effectively creating a single point of failure that can be exploited for malicious gain.

Citrix has acknowledged the issue but has yet to release a patch or workaround for affected customers. In the meantime, organizations relying on NetScaler and SAML should take immediate action to mitigate potential risks. This includes closely monitoring system logs, implementing robust access controls, and considering alternative security measures such as OAuth 2.0 or JWT-based authentication.

For those who rely heavily on SAML deployments, it’s essential to re-evaluate the security posture of their NetScaler infrastructure. Given the severity of this vulnerability, it may be prudent for organizations to consider transitioning away from NetScaler in favor of more secure alternatives. As always, vigilance and proactive security measures are key to preventing devastating attacks like these.


Source: The Hacker News — 2026-10-05