Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix Patches Critical Zero-Day Flaw Exploited in Targeted Attacks

Citrix has released emergency updates to fix a critical vulnerability, tracked as CVE-2026-88779, that has been exploited in zero-day attacks against unmitigated NetScaler deployments. The flaw, which affects NetScaler ADC and Gateway appliances using SAML authentication with Gateway or AAA functionality, can cause denial-of-service conditions, potentially leaving affected organizations without access to their services.

The vulnerability is a memory buffer flaw that allows attackers to crash the nsaaad process, leading to repeated forced reboots of affected appliances. According to Citrix, the company has observed targeted attacks against unmitigated NetScaler deployments, which have resulted in denial-of-service conditions. The CVSS score for this vulnerability is 8.7, indicating a high severity rating.

The impact of this vulnerability is significant, particularly for organizations that rely on their NetScaler appliances for authentication and authorization purposes. Citrix has provided patches to fix the flaw, including updates for NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28. For FIPS deployments, customers should upgrade to version 14.1-73.41 FIPS.

In addition to installing these security updates, Citrix recommends that organizations install Global Deny Lists to block access from known malicious IP addresses. However, the company emphasizes that upgrading to the latest patches is the most effective way to prevent exploitation of this vulnerability.

Researchers investigating the flaw have raised concerns that it may also be exploitable for remote code execution. While Citrix describes the vulnerability as a denial-of-service issue, NetScaler administrators and cybersecurity researchers have observed activity that indicates the flaw can be used to inject malicious code onto affected appliances. Further investigation is needed to confirm whether this is indeed possible.

The recent attacks were first reported by NetScaler administrators who noticed that their appliances were unexpectedly rebooting after installing patches for two other actively exploited vulnerabilities. The repeated crashes and reboots have led researchers to suspect that attackers are exploiting the CVE-2026-88779 flaw, rather than a bug in the recently released firmware.

In light of this vulnerability, it is essential for organizations using NetScaler appliances to take immediate action to protect themselves from potential attacks. Administrators should verify whether their appliances are configured with SAML authentication and check if they have installed the latest security updates. If an organization has already upgraded its NetScaler devices to fix previous vulnerabilities, it must upgrade them again to fix this flaw.

To prevent exploitation of this vulnerability, we recommend that organizations:

* Immediately install the latest patches for their NetScaler appliances

* Verify whether their appliances are configured with SAML authentication and apply necessary updates

* Install Global Deny Lists to block access from known malicious IP addresses

By taking these steps, organizations can minimize the risk of being targeted by attackers exploiting this critical vulnerability.


Source: Bleeping Computer — 2026-10-04