CyberSecurityNews

Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks


Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems.

The vulnerability carries a CVSS v4.0 score of 8.7 and affects appliances configured as a SAML service provider or identity provider. Citrix describes it as a memory overflow, classified under CWE-119, where software fails to keep memory operations within the bounds of a buffer.

Citrix confirmed targeted attacks against unmitigated deployments. Repeated exploitation can keep affected services unavailable. The company said its analysis showed an impact on service availability but had not identified any impact on the integrity of customer data. That distinction matters: the confirmed vendor assessment is denial of service, not proven data theft.

The CVSS vector indicates that attackers can reach the flaw over a network without login credentials or user interaction. Attack complexity is low, making exposed appliances with the required SAML configuration a priority for urgent updates.

Reports of trouble emerged as administrators saw recently patched appliances reboot repeatedly. Cyber Security News previously covered NetScaler reboots following the earlier zero-day patch, including failures tied to crafted SAML traffic that crashed the nsaaad authentication service. Some affected systems were already running build 14.1-73.37.

Investigators also reported authentication requests containing shell commands intended to download and run a payload. Those requests appeared before confirmed crashes, but the administrator examining them did not establish that the commands executed successfully.

Security researcher Kevin Beaumont separately reported a downloaded malware binary running on a patched honeypot, while watchTowr said it reproduced the vulnerability. These reports raise concerns about possible code execution, but they should not be confused with Citrix’s confirmed description of this CVE as a denial-of-service flaw.

Affected Versions and Configuration Checks

Citrix’s security bulletin lists NetScaler ADC and Gateway 14.1 releases before 14.1-73.41 and 13.1 releases before 13.1-64.28 as affected. NetScaler ADC FIPS releases before 14.1-73.41 FIPS are also vulnerable, alongside NetScaler ADC FIPS and NDcPP releases before 13.1-37.282.

Secure Private Access Hybrid deployments using affected NetScaler instances also require updates. The bulletin covers customer-managed systems; Cloud Software Group handles the necessary updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Administrators can check the configuration for add authentication samlAction, which identifies a SAML service provider, or add authentication samlIdPProfile, which identifies a SAML identity provider. Either entry meets the stated configuration requirement. Finding it shows potential exposure on an affected build, not proof that attackers have compromised the appliance.

Customers should install 14.1-73.41 or later on the 14.1 branch, or 13.1-64.28 or later on the 13.1 branch. FIPS customers need 14.1-73.41 FIPS or later, while 13.1 FIPS and NDcPP deployments require 13.1-37.282 or later within their respective branches.

Organizations that installed the previous NetScaler security updates must upgrade again if they meet this vulnerability’s conditions. Citrix is providing Global Deny Lists to block known malicious IP addresses, but still urges prompt patching. Its advisory credits Bishop Fox and watchTowr for helping protect customers.

For security teams, the immediate task is to match each appliance’s build and SAML settings against the bulletin, then apply the correct update. Recent patching alone is not enough: systems on earlier fixed builds can still face attacks targeting this newly disclosed SAML vulnerability.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC



Source link