Back
Citrix patches exploited NetScaler zero-day affecting SAML deployments
SiTech AI Team2 min read

Citrix patches exploited NetScaler zero-day affecting SAML deployments

Citrix has patched CVE-2026-88779, a NetScaler memory overflow exploited in targeted attacks that can cause denial of service in SAML deployments. CISA requires federal agencies to apply fixes by Oct. 7, 2026.

Citrix fixes exploited NetScaler vulnerability

Citrix has released security updates for CVE-2026-88779, a high-severity memory overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway. The vulnerability has a CVSS score of 8.7 out of 10.0 and has been exploited as part of targeted zero-day attacks.

Citrix said the flaw can lead to denial of service under specific deployment conditions. It affects customer-managed deployments running affected supported versions when the required preconditions are met. The company said repeated triggering of the condition can keep the service unavailable.

SAML configurations are affected

Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured as a SAML service provider or SAML identity provider. Customers can check whether the deployment meets the precondition by reviewing its configuration for the following entries: SAML SP - add authentication samlAction or SAML IdP - add authentication samlIdPProfile.

Citrix also said it was tracking a newly observed issue involving SAML authentication in customer-managed NetScaler deployments using SAML with Gateway or AAA functionality.

Fixed releases and CISA deadline

Fixed releases include NetScaler ADC and NetScaler Gateway 14.1-73.41 and later, version 13.1-64.28 and later in the 13.1 release line, NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Federal agencies are required to apply the patches by October 7, 2026.

Research and exploitation context

Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. watchTowr said it reproduced the flaw within hours of detecting NetScaler honeypot activity.

Citrix said its analysis indicated that the issue affects service availability and that it had not identified an impact on the integrity of customer data. The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.