Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this issue affects customer-managed NetScaler ADC and NetScaler Gateway devices and can cause service shutdowns, blocking access to services that rely on these systems.
The flaw has a CVSS v4.0 score of 8.7. It affects devices set up as a SAML service provider or identity provider. Citrix calls it a memory overflow. This falls under CWE-119, where software doesn’t manage memory operations within the limits of a buffer.
Citrix said there are attacks against systems that are not fixed. Ongoing exploitation can make services go down for a long time. The company found that service availability was affected but did not see any issues with customer data. This is important: the confirmed problem is denial of service, not data theft.
The CVSS vector shows that attackers can exploit the flaw through a network without needing passwords or user actions. The complexity is low, so devices with the needed SAML setup should receive urgent updates.
Investigators found requests to verify identity that had shell commands meant to download and run a program. These requests came before confirmed crashes, but the admin looking at them didn’t prove that the commands worked.
Security expert Kevin Beaumont reported a malware file running on a fixed honeypot. Meanwhile, watchTowr said they could recreate the issue. These findings worry about possible code running, but they are not the same as Citrix’s confirmed claim that this CVE is a denial-of-service problem.
Data breach protection Affected Versions and Configuration Checks
Citrix’s security notice names NetScaler ADC and Gateway versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28 as affected. NetScaler ADC FIPS versions before 14.1-73.41 FIPS are also at risk, along with NetScaler ADC FIPS and NDcPP versions before 13.1-37.282.
Secure private access hybrid setups with affected NetScaler instances need updates too. The bulletin is for customer-managed systems. Cloud Software Group takes care of updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication.
Administrators can check the configuration for add authentication samlAction, which identifies a SAML service provider, or add authentication samlIdPProfile, which identifies a SAML identity provider. Either entry meets the stated configuration requirement. Finding it shows potential exposure on an affected build, not proof that attackers have compromised the appliance.
Customers must install 14.1-73.41 or newer on the 14.1 branch, or 13.1-64.28 or newer on the 13.1 branch. FIPS customers need 14.1-73.41 FIPS or newer. Also, 13.1 FIPS and NDcPP deployments need 13.1-37.282 or newer in their branches.
Organizations that updated their NetScaler security before need to upgrade again if they fit this vulnerability’s conditions. Citrix is giving out Global Deny Lists to block bad IP addresses, but still advises quick patching. The advisory thanks Bishop Fox and watchTowr for their help in protecting customers.
For security teams, the first job is to compare each appliance’s setup and SAML settings with the bulletin, then make the right update. Just recent patches are not enough: systems on old fixed builds can still be attacked because of this new SAML weakness.
InfoSecBulletin Cybersecurity for mankind
