← Back to news
BleepingComputer4 Oct 2026 · 2 min read

Citrix issues emergency NetScaler update for exploited SAML flaw

Citrix has released security updates for an actively exploited vulnerability in NetScaler ADC and NetScaler Gateway appliances that use SAML authentication. The issue, tracked as CVE-2026-88779, is ra...

Citrix has released security updates for an actively exploited vulnerability in NetScaler ADC and NetScaler Gateway appliances that use SAML authentication. The issue, tracked as CVE-2026-88779, is rated 8.7 out of 10 and can cause affected services to become unavailable.

According to Citrix, the flaw is a memory-buffer issue affecting deployments configured for Gateway or AAA functions with SAML acting as either a service provider or identity provider. The company said it has seen targeted exploitation of unpatched systems and warned that repeated triggering of the condition may leave services unavailable. Citrix said its investigation has not identified an effect on customer-data integrity.

Updates and affected configurations

The vendor released NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28 to address the issue. Customers using FIPS deployments should move to version 14.1-73.41 FIPS, while 13.1 FIPS and NDcPP users should install version 13.1-37.282.

Administrators can review their configurations for SAML-related settings, including authentication samlAction and authentication samlIdPProfile. Citrix is also distributing Global Deny Lists intended to block known malicious addresses, but said patching is the primary recommended action. Organizations that recently updated systems for earlier NetScaler flaws may need to update again if they meet the SAML preconditions.

Reports raise questions about code execution

While Citrix characterizes CVE-2026-88779 as a denial-of-service vulnerability, researchers and administrators have reported activity suggesting attackers may be probing for broader impact. Reports described repeated crashes involving the NetScaler authentication service and subsequent appliance reboots, including on systems running earlier patched releases.

One administrator identified crafted authentication values containing apparent shell-command payloads designed to download and run a file. The observed requests coincided with crashes, but did not establish that the commands executed successfully. Separately, researcher Kevin Beaumont reported that a patched honeypot appeared to run a downloaded malicious binary. watchTowr Labs said it reproduced the vulnerability but has not published technical details.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to mitigate it by October 7. Organizations running exposed NetScaler appliances should apply the available updates promptly and review authentication and appliance logs for unusual crashes or suspicious SAML requests.

Share this article:TwitterLinkedIn