Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779, which can deny service on ADC and Gateway appliances.
Citrix issued emergency updates for CVE-2026-88779, a NetScaler SAML memory-overflow zero-day that attackers are actively exploiting against customer-managed ADC and Gateway appliances. The flaw, CVSS v4.0 8.7 and CWE-119, is reachable over the network without credentials or user interaction when the appliance is a SAML service provider or identity provider, and Citrix says confirmed impact is denial of service rather than data integrity loss. Affected builds include 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, and listed FIPS and NDcPP releases; fixed builds are 14.1-73.41, 13.1-64.28, and corresponding FIPS updates. Bishop Fox and watchTowr were credited. Separate reports of shell commands and a honeypot malware binary raise code-execution concerns but are not Citrix’s confirmed description of this CVE.
- CVE-2026-88779 is a SAML memory overflow (CWE-119) scored CVSS 8.7.
- Citrix confirmed targeted attacks causing denial of service, not proven data theft.
- Affects customer-managed ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28.
- Reachable over the network without credentials when configured as SAML SP or IdP.
- Separate honeypot reports suggest possible code execution but are not Citrix’s confirmed impact.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article623 words · extracted from cybersecuritynews.com · click to collapse
Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems.
The vulnerability carries a CVSS v4.0 score of 8.7 and affects appliances configured as a SAML service provider or identity provider. Citrix describes it as a memory overflow, classified under CWE-119, where software fails to keep memory operations within the bounds of a buffer.
Citrix confirmed targeted attacks against unmitigated deployments. Repeated exploitation can keep affected services unavailable. The company said its analysis showed an impact on service availability but had not identified any impact on the integrity of customer data. That distinction matters: the confirmed vendor assessment is denial of service, not proven data theft.
The CVSS vector indicates that attackers can reach the flaw over a network without login credentials or user interaction. Attack complexity is low, making exposed appliances with the required SAML configuration a priority for urgent updates.
Reports of trouble emerged as administrators saw recently patched appliances reboot repeatedly. Cyber Security News previously covered NetScaler reboots following the earlier zero-day patch, including failures tied to crafted SAML traffic that crashed the nsaaad authentication service. Some affected systems were already running build 14.1-73.37.
Investigators also reported authentication requests containing shell commands intended to download and run a payload. Those requests appeared before confirmed crashes, but the administrator examining them did not establish that the commands executed successfully.
Security researcher Kevin Beaumont separately reported a downloaded malware binary running on a patched honeypot, while watchTowr said it reproduced the vulnerability. These reports raise concerns about possible code execution, but they should not be confused with Citrix’s confirmed description of this CVE as a denial-of-service flaw.
Affected Versions and Configuration Checks
Citrix’s security bulletin lists NetScaler ADC and Gateway 14.1 releases before 14.1-73.41 and 13.1 releases before 13.1-64.28 as affected. NetScaler ADC FIPS releases before 14.1-73.41 FIPS are also vulnerable, alongside NetScaler ADC FIPS and NDcPP releases before 13.1-37.282.
Secure Private Access Hybrid deployments using affected NetScaler instances also require updates. The bulletin covers customer-managed systems; Cloud Software Group handles the necessary updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
Administrators can check the configuration for add authentication samlAction, which identifies a SAML service provider, or add authentication samlIdPProfile, which identifies a SAML identity provider. Either entry meets the stated configuration requirement. Finding it shows potential exposure on an affected build, not proof that attackers have compromised the appliance.
Customers should install 14.1-73.41 or later on the 14.1 branch, or 13.1-64.28 or later on the 13.1 branch. FIPS customers need 14.1-73.41 FIPS or later, while 13.1 FIPS and NDcPP deployments require 13.1-37.282 or later within their respective branches.
Organizations that installed the previous NetScaler security updates must upgrade again if they meet this vulnerability’s conditions. Citrix is providing Global Deny Lists to block known malicious IP addresses, but still urges prompt patching. Its advisory credits Bishop Fox and watchTowr for helping protect customers.
For security teams, the immediate task is to match each appliance’s build and SAML settings against the bulletin, then apply the correct update. Recent patching alone is not enough: systems on earlier fixed builds can still face attacks targeting this newly disclosed SAML vulnerability.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.