New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix patched exploited NetScaler CVE-2026-88779, a SAML memory overflow that can deny service.
Citrix patched CVE-2026-88779, a CVSS 8.7 memory-overflow flaw in customer-managed NetScaler ADC and NetScaler Gateway that can deny service when the appliance is configured as a SAML service provider or identity provider. Citrix said targeted attacks hit unpatched deployments and that repeated triggering can keep the service unavailable, with no identified impact on customer-data integrity. Fixes are in 14.1-73.41, 13.1-64.28, and corresponding 14.1-FIPS and 13.1-FIPS/NDcPP releases; Bishop Fox and watchTowr were credited. CISA added the CVE to the KEV catalog and required federal agencies to patch by October 7, 2026. The report also notes earlier exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools.
- CVE-2026-88779 is a CVSS 8.7 NetScaler memory overflow causing denial of service.
- Exploitation requires a SAML service-provider or identity-provider configuration.
- Citrix confirmed targeted attacks; CISA KEV deadline is October 7, 2026.
- Fixed releases include 14.1-73.41, 13.1-64.28, and matching FIPS/NDcPP builds.
- Citrix found no customer-data integrity impact; the effect is availability.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article399 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 05, 2026Zero-Day / Vulnerability
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.
The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.
"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."
For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following -
- SAML SP - add authentication samlAction
- SAML IdP - add authentication samlIdPProfile
The issue has been addressed in the following versions -
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. In a post shared on X, watchTowr said it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity.
"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service," the company acknowledged. "If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."
The patches come after Citrix said it's tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it's related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.
The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.