Oct 5 / Latest News

Citrix Warns of Targeted Attacks on NetScaler SAML Deployments, Issues Fixes

Citrix released security updates for a high‑severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway after confirming targeted zero‑day exploitation against unmitigated customer‑managed deployments.

Tracked as CVE‑2026‑88779 with a CVSS score of 8.7, the flaw can trigger denial‑of‑service under specific deployment conditions. Citrix said exploitation requires NetScaler ADC or Gateway to be configured as either a SAML service provider (SP) or SAML identity provider (IdP). Customers can verify exposure by checking for configuration entries such as add authentication samlAction for SP or add authentication samlIdPProfile for IdP.

The issue has been addressed in NetScaler ADC and Gateway versions 14.1‑73.41 and later, 13.1‑64.28 and later, 14.1‑FIPS 14.1‑73.41 and later, and 13.1‑FIPS/13.1‑NdC PP 13.1‑37.282 and later. Citrix credited Bishop Fox and watchTowr for reporting the vulnerability.

Citrix acknowledged observing targeted attacks on unpatched deployments, noting that repeated triggering of the condition can render services unavailable. The company said its analysis shows an impact on service availability but no evidence of compromise to customer data integrity. The patches follow Citrix’s earlier notice about a newly observed issue related to SAML authentication in customer‑managed NetScaler environments, particularly those using SAML with Gateway or AAA functionality.

The development also comes amid active exploitation of other NetScaler vulnerabilities, including CVE‑2026‑88771 and CVE‑2026‑88772, which have been used to deploy web shells and tunneling tools on compromised systems. CISA has added CVE‑2026‑88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply patches by October 7, 2026.