VMTech
Discuss a project →

Citrix patches exploited NetScaler SAML denial-of-service flaw

Citrix patches exploited NetScaler SAML denial-of-service flaw

Citrix has released security updates for CVE-2026-88779, a high-severity memory-overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway that has been exploited in targeted attacks. The flaw has a CVSS score of 8.7 and can cause denial of service in customer-managed deployments that use specified SAML authentication configurations.

Citrix said attackers have targeted unmitigated NetScaler deployments. When the condition is triggered repeatedly, the affected service may remain unavailable. The company said its analysis identified an impact on service availability and did not identify an impact on the integrity of customer data.

SAML configuration determines exposure

Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured as either a SAML service provider or a SAML identity provider. Administrators can check for the relevant preconditions in their configuration by looking for the entries add authentication samlAction, for a SAML service provider, and add authentication samlIdPProfile, for a SAML identity provider.

The issue concerns customer-managed supported versions of the products when those deployment conditions are present. Citrix had already said it was tracking a newly observed SAML authentication issue affecting customer-managed NetScaler environments that use SAML with Gateway or AAA functionality.

Patched NetScaler releases

Citrix has addressed the vulnerability in NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases, as well as NetScaler ADC and NetScaler Gateway 13.1-64.28 and later 13.1 releases. For NetScaler ADC 14.1-FIPS, the fixed version is 14.1-73.41 FIPS and later. For NetScaler ADC 13.1-FIPS and 13.1-NDcPP, the update is 13.1-37.282 and later releases.

Citrix credited Bishop Fox and watchTowr with reporting the issue. watchTowr said it reproduced the vulnerability within hours of detecting activity against NetScaler honeypots. The disclosure follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to deploy web shells and tunnelling tools on compromised systems.

Federal deadline and operational response

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Federal civilian agencies are required to apply the patches by October 7, 2026.

For organisations operating customer-managed NetScaler systems, the practical priority is to identify SAML-enabled ADC and Gateway deployments, verify whether they run an affected release, and install the applicable Citrix update. Because the documented consequence is sustained service unavailability, patch planning should account for the business systems that depend on SAML authentication and Gateway or AAA access.

#cybersecurity#netscaler#saml#vulnerability
Open analytics
On the site 0 views
min read 3 05.10.2026
Instagram

Citrix patches exploited NetScaler SAML denial-of-service flaw

Open the post on Instagram ↗