Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks
Citrix patched CVE-2026-88779, a CVSS 8.7 unauthenticated NetScaler SAML memory overflow enabling persistent remote DoS, reportedly exploited in targeted attacks.
Citrix issued emergency updates for CVE-2026-88779, a CWE-119 memory overflow in NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication as SP or IdP, rated CVSS v4 8.7. The flaw is network-exploitable with low attack complexity, requires no authentication or user interaction, and impacts availability by crashing the appliance or service. Fixes are available in 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 (FIPS/NDcPP) builds, and exploitation has been reported in targeted attacks against unmitigated deployments. Bishop Fox and watchTowr are credited for the discovery.
- CVE-2026-88779: unauthenticated memory overflow rated CVSS v4 8.7
- Only affects appliances with SAML SP (samlAction) or IdP (samlIdPProfile) config
- Fixed in 14.1-73.41, 13.1-64.28, and matching FIPS/NDcPP builds
- Targeted exploitation reported; review crashes, reboots, and SAML auth logs
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article450 words · extracted from gbhackers.com · click to collapse
Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
This flaw, tracked as CVE-2026-88779, could allow unauthenticated remote attackers to cause persistent denial-of-service conditions.
The vulnerability specifically affects appliances configured for SAML authentication, whether set as a Service Provider (SP) or an Identity Provider (IdP).
Cloud Software Group has assigned a CVSS v4 base score of 8.7 to this issue and categorized it as CWE-119, which refers to improper restriction of operations within the bounds of a memory buffer.
The published vector indicates that this flaw can be exploited over the network with low attack complexity and does not require authentication or user interaction. Its assessed impact is primarily on availability.
Citrix NetScaler SAML Vulnerability
CVE-2026-88779 is relevant only when NetScaler ADC or Gateway is set up to process SAML authentication. Citrix specifies that an appliance meets the vulnerability precondition if its configuration includes either of the following entries:
- `add authentication samlAction` (indicating a SAML SP configuration)
- `add authentication samlIdPProfile` (indicating a SAML IdP deployment)
Organizations utilizing NetScaler Gateway or AAA functions for federated authentication should prioritize patching any externally reachable SAML-enabled appliances.
This memory overflow issue can cause a device or service to crash. If triggered repeatedly, it may disrupt remote-access portals, identity flows, and applications that rely on the NetScaler appliance for authentication and traffic delivery.
Affected Versions and Fixes
Citrix identifies the following vulnerable product branches:
| Product branch | Vulnerable before | Fixed release |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.41 | 14.1-73.41 or later |
| NetScaler ADC and Gateway 13.1 | 13.1-64.28 | 13.1-64.28 or later |
| NetScaler ADC 14.1-FIPS | 14.1-73.41 FIPS | 14.1-73.41 FIPS or later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1-37.282 | 13.1-37.282 or later |
Citrix strongly urges affected customers to install the appropriate fixed build as soon as possible. NetScaler Console users can identify impacted instances through its CVE Detection workflow and initiate an upgrade from the affected instance view.
The vulnerability has been reported to be exploited in targeted attacks against unmitigated deployments. While Citrix assesses that the flaw primarily affects availability and does not compromise customer data integrity, widespread gateway disruptions can have significant operational impacts, especially for organizations relying on NetScaler for VPN, workforce access, and SSO services.
Teams should also review appliance crash events, unexpected reboots, SAML-related authentication failures, nsaaad service behavior, firewall telemetry, and identity-provider logs for signs of attempted exploitation.
Finally, Citrix acknowledges Bishop Fox and watchTowr’s collaboration in addressing this issue.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.