SecPod

Learn Search

Search across all Learn content

← Back to Security Research
New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

Citrix has disclosed CVE-2026-88779, a high-severity memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Targeted attacks on unmitigated deployments have been observed. This article covers impact, affected versions, configuration checks, temporary Global Deny List guidance, and fixed builds.

Oct 8, 2026By Bapanapalli Prem Sai Siddhik
vulnerability research

Summary

Citrix has published security bulletin CTX697174 for CVE-2026-88779, a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that can lead to denial of service. The issue applies when the appliance is configured as a SAML service provider or SAML identity provider. Citrix has observed targeted attacks on unmitigated deployments. The vulnerability has also been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Customers should review configuration against the published preconditions and install the fixed builds as soon as possible.

Vulnerability Details

CVE ID CVSS Score EPSS Score Type
CVE-2026-88779 8.7 0.592% CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Technical Information

High Zero-Day Unauthenticated No User Interaction Actively Exploited DoS

CVE-2026-88779 — Memory Overflow Leading to Denial of Service

The issue is a memory overflow in Citrix NetScaler ADC and Citrix NetScaler Gateway. Under the published SAML-related configuration, processing of traffic can trigger the condition and result in denial of service. Citrix has observed targeted attacks against unmitigated deployments that lead to this outcome. If the condition is triggered repeatedly, the service may remain unavailable until recovery actions are taken.

Citrix’s analysis indicates the impact is limited to service availability. The company has not identified an impact on the integrity of customer data. That differs from the earlier NetScaler issues tracked as CVE-2026-88771 and CVE-2026-88772, which involved remote code execution paths in addition to availability concerns.

Exposure depends on how the appliance is configured, not on version alone. The published precondition is that NetScaler ADC or NetScaler Gateway is configured as a SAML service provider (SP) or SAML identity provider (IdP). Citrix associates the issue with SAML authentication used together with Gateway or AAA functionality. Deployments that do not use SAML in these roles fall outside the published precondition path.

How to check the precondition: Inspect the NetScaler configuration for either of the following:

  • Configured as a SAML SP: add authentication samlAction
  • Configured as a SAML IdP: add authentication samlIdPProfile

Customers who already applied builds released for the earlier bulletin covering CVE-2026-88771 through CVE-2026-88778 may still need a further upgrade if the SAML precondition applies. Those earlier fixed builds do not include the remediation for this issue.

The bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. Cloud Software Group upgrades Citrix-managed cloud services, including Gateway Service and Citrix-managed Adaptive Authentication.

Impact

  • Denial of service
    Targeted attacks against unmitigated deployments can disrupt service availability. Repeated triggering can leave the service unavailable. Citrix states that integrity of customer data has not been identified as impacted.

Affected Versions

The following supported versions are affected when the SAML SP or SAML IdP precondition applies:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.28
  • Citrix NetScaler ADC FIPS before 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.282

This bulletin applies only to customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway. Cloud Software Group upgrades Citrix-managed cloud services, including Gateway Service and Citrix-managed Adaptive Authentication.

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic ID Tactic
T1190 Exploit Public-Facing Application TA0001 Initial Access
T1498 Network Denial of Service TA0040 Impact

Mitigation and Recommendations

Citrix strongly urges customers to install the latest fixed versions as soon as possible.

Fixed Builds

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.41 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Temporary mitigation

Citrix has released signatures that can be used with the Global Deny List feature to help reduce exposure while planning an upgrade. Global Deny List is enabled by default on NetScaler software starting with 14.1-60.52 and 13.1-63.21. Prerequisites include NetScaler Console (on-premises with Cloud Connect, or service) with Virtual patching enabled, and software in one of these ranges before the fixed builds:

  • 14.1: greater than or equal to 14.1-73.37 and less than 14.1-73.41
  • 13.1: greater than or equal to 13.1-64.23 and less than 13.1-64.28

Verify signatures with show appfw signatures (Default Signatures encrypted version at least v24) and stat denylist global AAA_REQUEST. Global Deny List helps mitigate the issue; upgrading to a fixed build remains the recommended remediation.

Recommended Actions

  • Confirm whether the deployment is configured as a SAML SP or SAML IdP using the configuration patterns above.
  • Upgrade customer-managed appliances that meet the precondition to a fixed build listed above.
  • If the appliance was already upgraded for the earlier bulletin covering CVE-2026-88771 through CVE-2026-88778 and still meets the SAML precondition, upgrade again to a build that includes the fix for CVE-2026-88779.
  • Where appropriate, use NetScaler blocklist functionality and perimeter controls to limit traffic from sources of attack activity.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026

Open Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
vulnerability researchCritical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

CVE Research

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026