MikhbarMIKHBAR
Cybersecurity

Citrix Patches NetScaler SAML Zero-Day Exploited in Attacks

Citrix has rushed out emergency updates to address a new zero-day vulnerability in NetScaler ADC and NetScaler Gateway appliances, which is actively being exploited in the wild.

Citrix Patches NetScaler SAML Zero-Day Exploited in Attacks

Emergency Patches Issued for NetScaler Zero-Day

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. According to BleepingComputer, the vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality.

The Citrix security advisory indicates that the vulnerability carries a CVSS score of 8.7 and has been actively leveraged in targeted attacks against unmitigated NetScaler deployments, resulting in denial-of-service conditions. Citrix said that repeated triggering of the condition can leave the service unavailable, though analysis points to an impact solely on service availability without compromising customer data integrity.

Release Versions and Mitigation Guidance

Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28 to remediate the CVE-2026-88779 zero-day flaw. For FIPS deployments, customers are instructed to upgrade to version 14.1-73.41 FIPS. Meanwhile, NetScaler ADC FIPS and NDcPP customers utilizing the 13.1 branch should install version 13.1-37.282.

Alongside software updates, Citrix is supplying Global Deny Lists designed to block traffic from identified malicious IP addresses. However, the vendor strongly advises customers to deploy the newly issued security updates as quickly as possible. Organizations can verify vulnerability by checking whether SAML authentication is configured via authentication samlAction or authentication samlIdPProfile settings.

Unfortunately, organizations that recently updated their NetScaler equipment to address two actively exploited vulnerabilities must apply updates once again to resolve this new flaw. Citrix noted that deployments already patched for CVE-2026-88771 through CVE-2026-88778 must undergo another upgrade cycle if they meet the specific preconditions.

Researchers Investigate Potential Remote Code Execution

While Citrix has officially characterized CVE-2026-88779 as a denial-of-service issue, cybersecurity researchers and NetScaler administrators have observed behavioral indicators suggesting the vulnerability could potentially be used for remote code execution. Initial incident reports surfaced when administrators noticed recently patched appliances undergoing unexpected reboots.

Discussions on a Reddit thread highlighted multiple instances where appliances running NetScaler 14.1-73.37 experienced repeated forced reboots despite running the latest available firmware. Another Reddit thread detailed situations where nsaaad crashed continuously until the NetScaler Pitboss process hit its restart limit and forced an appliance reboot.

Subsequent investigation by an administrator revealed authentication usernames containing shell commands designed to download and execute an external payload. Cybersecurity expert Kevin Beaumont also observed similar crash patterns on honeypots, noting that activity escalated beyond simple denial-of-service when a patched honeypot successfully executed a downloaded malware binary.

Beaumont pointed out that CVE-2026-88779 shares similarities with how previous critical flaws were initially classified before researchers discovered they could be leveraged for remote code execution. Security firm watchTowr Labs also confirmed the reproducibility of the vulnerability.

Official Advisories and CISA Action

As investigations progressed, Citrix published a security notice on Friday informing customers about a newly observed issue impacting SAML authentication configurations. The vendor advised organizations experiencing unusual reboots or crashes to reach out directly to Citrix support.

In response to active exploitation, CISA formally added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Federal civilian executive branch agencies have been given a strict deadline to implement required patches and mitigate the associated security risks.

Sources

Continue chronologically

You are readingCitrix Patches NetScaler SAML Zero-Day Exploited in Attacks
Technical University of Denmark Breach Exposes Data for 200,000
Older storyTechnical University of Denmark Breach Exposes Data for 200,000October 3, 2026 · 4 min