Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.

The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality.

The Citrix security advisory says the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial-of-service conditions.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," Citrix said in a related blog post published today.

"If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."

Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix the CVE-2026-88779 zero-day flaw.

For FIPS deployments, customers should upgrade to 14.1-73.41 FIPS. NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282.

Citrix is also providing Global Deny Lists that will block access from known malicious IP addresses. However, the company recommends that customers install the newly released security updates as soon as possible.

The company says organizations can determine if their appliances are vulnerable to the flaw by checking whether SAML authentication is configured:

  • Appliance is configured as a SAML SP add authentication samlAction OR  
  • Appliance is configured as a SAML IdP add authentication samlIdPProfile

Unfortunately, organizations that recently upgraded NetScaler devices to fix two actively exploited vulnerabilities must upgrade them again to fix this flaw.

"If you upgraded your NetScaler deployment with one of the updated software releases identified in the security bulletin for CVE 2026-88771 through CVE 2026-88778, and if you have determined that your NetScaler deployment meets the preconditions describe above, please upgrade your deployment again," Citrix warned.

Researchers investigate possible code execution

While Citrix describes CVE-2026-88779 as a denial-of-service vulnerability, NetScaler administrators and cybersecurity researchers have seen activity that indicates the flaw can be used for remote code execution.

The new attacks were first reported on Thursday after NetScaler administrators reported that recently patched appliances were unexpectedly rebooting.

In a Reddit thread, one NetScaler admin said multiple customers running NetScaler 14.1-73.37 were experiencing repeated forced reboots despite having installed the latest security updates available at the time.

Other administrators quickly reported similar behavior, including on appliances rebuilt from fresh images. Another Reddit thread said nsaaad was repeatedly crashing until NetScaler's Pitboss process reached its restart limit and rebooted the appliance.

At first, it was unclear whether vulnerability scanners were triggering a bug in recently released firmware or whether attackers were actively exploiting new flaws in NetScaler devices.

However, one administrator investigating these incidents on NetScaler 14.1-73.37 devices saw crafted authentication usernames containing shell commands that download a payload from the IP address 213.209.159[.]55, save it as /v, and execute the file.

According to the administrator, these requests appeared immediately before three confirmed nsaaad crash sequences on one appliance and targeted multiple SAML authentication factors.

The administrator stressed that the logs showed attempted exploitation and correlated crashes but did not confirm that the commands were successfully executed.

Other administrators reported the same nsaaad and Pitboss crash patterns, including on systems already upgraded to version 14.1-73.37.

As administrators continued investigating the crashes, Citrix published a security notice on Friday saying its engineering and support teams were tracking a "newly observed issue" related to SAML authentication in customer-managed NetScaler deployments.

The company said affected configurations contain either an authentication samlAction or authentication samlIdPProfile setting and advised customers experiencing the issue to contact Citrix support.

Citrix also confirmed that the issue was different from the previously disclosed NetScaler vulnerabilities.

Cybersecurity expert Kevin Beaumont also reported that patched NetScaler 13.1 and 14.1 honeypots were crashing after receiving requests from multiple source IP addresses, describing the activity as potentially another "PitScaler" vulnerability.

He later said the activity appeared to go further than just denial-of-service, after finding that one of his patched honeypots was running a downloaded malware payload.

"So on one of the honeypots it’s running a downloaded (malware) binary. Both were patched, so new vuln," Beaumont said.

"It’s being sprayed and prayed. One of the honeypots doesn’t even have a valid SSL certificate as I let it expire."

Beaumont also said that CVE-2026-88779 was described as a "Memory overflow vulnerability leading to Denial of Service," similar to how the previously disclosed CVE-2025-6543 was initially characterized before later attacks showed it could be used for remote code execution.

Cybersecurity company watchTowr Labs also confirmed that it reproduced the vulnerability after initially investigating reports of NetScaler honeypot activity.

The researchers have not yet disclosed technical details about how they reproduced the flaw.

On Sunday, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming the flaw is being actively exploited and giving FCEB agencies until October 7 to mitigate it.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dive deeper

Free tools to verify and analyze what this article covers:

source: BleepingComputer