
Citrix fixes NetScaler SAML Zero Day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial of service vulnerability identified as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.
The vulnerability is a buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality.
The Citrix security advisory states that the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial of service conditions.
“Citrix has observed targeted attacks on unmitigated NetScaler deployments that can lead to a denial of service,” Citrix said in a blog post published today.
“If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability and we have not identified any impact on the integrity of customer data.”
Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix zero-day CVE-2026-88779.
For FIPS deployments, customers should upgrade to FIPS version 14.1-73.41. NetScaler ADC FIPS and NDcPP clients on branch 13.1 should install 13.1-37.282.
Citrix also provides global deny lists that will block access from known malicious IP addresses. However, the company recommends that customers install new security updates as soon as possible.
The company says organizations can determine if their devices are vulnerable to the flaw by checking whether SAML authentication is configured:
- The appliance is configured as a SAML SP
add authentication samlActionOR
- The appliance is configured as a SAML identity provider
add authentication samlIdPProfile
Unfortunately, organizations that recently upgraded their NetScaler devices to fix two actively exploited vulnerabilities must upgrade them again to fix this flaw.
“If you have upgraded your NetScaler deployment with one of the updated software versions identified in the security bulletin for CVE 2026-88771 to CVE 2026-88778, and you have determined that your NetScaler deployment meets the prerequisites described above, please upgrade your deployment again,” Citrix warned.
Researchers study possible code execution
While Citrix describes CVE-2026-88779 as a denial of service vulnerability, NetScaler administrators and cybersecurity researchers have seen activity indicating that the flaw can be used for remote code execution.
The new attacks were first reported on Thursday after NetScaler administrators reported that newly patched devices were rebooting unexpectedly.
In a Reddit thread, a NetScaler administrator said that several clients running NetScaler 14.1-73.37 were experiencing repeated forced reboots despite installing the latest security updates available at the time.
Other administrators quickly reported similar behavior, particularly on devices rebuilt from new images. Another Reddit thread said nsaaad crashed repeatedly until the NetScaler Pitboss process reached its restart limit and restarted the appliance.
At first, it was unclear whether the vulnerability scanners were triggering a bug in the recently released firmware or whether the attackers were actively exploiting new flaws in NetScaler devices.
However, an administrator investigating these incidents on NetScaler 14.1-73.37 devices discovered crafted authentication usernames containing shell commands that download a payload from the IP address 213.209.159(.)55, save it as /v, and execute the file.
According to the administrator, these requests appeared just before three confirmed nsaaad crash sequences on an appliance and targeted multiple SAML authentication factors.
The administrator pointed out that the logs showed exploit attempts and correlated crashes, but did not confirm that the commands were executed successfully.
Other admins have reported the same crash patterns of nsaaad and Pitboss, including on systems already upgraded to version 14.1-73.37.
As administrators continued their investigation into the crashes, Citrix issued a security advisory Friday saying its engineering and support teams were monitoring a “newly observed issue” related to SAML authentication in customer-managed NetScaler deployments.
The company stated that the affected configurations contain either a authentication samlAction Or authentication samlIdPProfile setting and advised customers experiencing this issue to contact Citrix Support.
Citrix also confirmed that the issue was different from previously disclosed NetScaler vulnerabilities.
Cybersecurity expert Kevin Beaumont also reported that patched NetScaler 13.1 and 14.1 honeypots were crashing after receiving requests from multiple source IP addresses, describing the activity as potentially another “PitScaler” vulnerability.
He later said the activity appeared to go deeper than a simple denial of service, after discovering that one of his patched honeypots was running a downloaded malware payload.
“So on one of the honeypots it’s running a downloaded (malware) binary. Both have been patched, so a new vulnerability,” Beaumont said.
“It’s sprayed and prayed. One of the honeypots doesn’t even have a valid SSL certificate because I let it expire.”
Beaumont also said that CVE-2026-88779 was described as a “memory overflow vulnerability leading to denial of service,” similar to how the previously disclosed CVE-2025-6543 was initially characterized before later attacks showed it could be used for remote code execution.
Cybersecurity firm watchTowr Labs also confirmed that it reproduced the vulnerability after initially investigating activity reports from the NetScaler honeypot.
The researchers have not yet disclosed technical details about how they reproduced the flaw.
On Sunday, CISA added CVE-2026-88779 to its catalog of known exploited vulnerabilities, confirming that the flaw is being actively exploited and giving FCEB agencies until October 7 to mitigate it.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL and Atlassian for a two-hour digital summit on what attacks change at AI speed, what defenders should stop doing and how to validate, decide, remediate and revalidate at machine speed.
Save your place
Gn bussni