Citrix: Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks

Citrix: Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks

Citrix Patches High-Severity NetScaler SAML Vulnerability (CVE-2026-88779)

Citrix has released emergency security updates to address CVE-2026-88779, a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable unauthenticated remote attackers to trigger persistent denial-of-service (DoS) conditions.

The flaw, rated 8.7 (CVSS v4), stems from improper memory buffer restrictions (CWE-119) and affects appliances configured for SAML authentication whether as a Service Provider (SP) or Identity Provider (IdP). Exploitation requires no authentication or user interaction, with low attack complexity, and primarily impacts availability by crashing devices or services.

Affected Configurations & Impact

The vulnerability applies only to NetScaler deployments with SAML authentication enabled, identifiable by the following configuration entries:

  • add authentication samlAction (SAML SP)
  • add authentication samlIdPProfile (SAML IdP)

Successful exploitation could disrupt remote-access portals, identity flows, and applications reliant on NetScaler for authentication or traffic delivery. While Citrix confirms the flaw does not compromise data integrity, repeated attacks may cause operational outages, particularly for organizations using NetScaler for VPN, workforce access, or SSO services.

Vulnerable Versions & Fixes

Citrix has released patched versions for the following branches:

Product Branch Vulnerable Before Fixed Release
NetScaler ADC & Gateway 14.1 14.1-73.41 14.1-73.41 or later
NetScaler ADC & Gateway 13.1 13.1-64.28 13.1-64.28 or later
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS 14.1-73.41 FIPS or later
NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.282 13.1-37.282 or later

NetScaler Console users can detect impacted instances via the CVE Detection workflow and initiate upgrades directly.

Exploitation & Mitigation

Citrix reports targeted attacks against unpatched deployments. Security teams are advised to:

  • Review appliance logs for crash events, unexpected reboots, SAML authentication failures, or anomalous nsaaad service behavior.
  • Monitor firewall telemetry and identity-provider logs for signs of exploitation.

The vulnerability was addressed with contributions from Bishop Fox and watchTowr. Organizations using SAML-enabled NetScaler appliances for federated authentication should prioritize patching externally exposed instances.

Source: https://gbhackers.com/citrix-netscaler-saml-vulnerability/

Citrix TPRM report: https://www.rankiteo.com/company/citrix

"id": "cit1791181418",
"linkid": "citrix",
"type": "Vulnerability",
"date": "10/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Organizations using NetScaler '
                                              'ADC and NetScaler Gateway with '
                                              'SAML authentication enabled',
                        'industry': 'Technology/Software',
                        'name': 'Citrix',
                        'type': 'Vendor'}],
 'attack_vector': 'Remote',
 'description': 'Citrix has released emergency security updates to address '
                'CVE-2026-88779, a high-severity memory overflow vulnerability '
                'in NetScaler ADC and NetScaler Gateway that could enable '
                'unauthenticated remote attackers to trigger persistent '
                'denial-of-service (DoS) conditions. The flaw affects '
                'appliances configured for SAML authentication as a Service '
                'Provider (SP) or Identity Provider (IdP).',
 'impact': {'downtime': 'Persistent DoS conditions, operational outages',
            'operational_impact': 'Disruption of remote-access portals, '
                                  'identity flows, and applications reliant on '
                                  'NetScaler for authentication or traffic '
                                  'delivery',
            'systems_affected': 'NetScaler ADC and NetScaler Gateway with SAML '
                                'authentication enabled'},
 'post_incident_analysis': {'corrective_actions': 'Apply security patches, '
                                                  'review and update SAML '
                                                  'configurations, enhance '
                                                  'monitoring for exploitation '
                                                  'attempts',
                            'root_causes': 'Improper memory buffer '
                                           'restrictions (CWE-119) in SAML '
                                           'authentication configurations'},
 'recommendations': 'Prioritize patching externally exposed instances, review '
                    'appliance logs for signs of exploitation, and monitor '
                    'identity-provider logs.',
 'references': [{'source': 'Citrix Security Bulletin'},
                {'source': 'Bishop Fox'},
                {'source': 'watchTowr'}],
 'response': {'containment_measures': 'Patch deployment, log review for crash '
                                      'events or anomalous behavior',
              'enhanced_monitoring': 'Monitor firewall telemetry and '
                                     'identity-provider logs for signs of '
                                     'exploitation',
              'remediation_measures': 'Apply security updates to vulnerable '
                                      'NetScaler versions',
              'third_party_assistance': 'Bishop Fox, watchTowr'},
 'title': 'Citrix Patches High-Severity NetScaler SAML Vulnerability '
          '(CVE-2026-88779)',
 'type': 'Vulnerability',
 'vulnerability_exploited': 'CVE-2026-88779 (Memory Overflow - CWE-119)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.