securityonline.info 4 Oct 2026, 08:21 UTC

Citrix NetScaler Flaw Exploited to Knock SAML Gateways Offline

Citrix NetScaler Flaw Exploited to Knock SAML Gateways Offline
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

CITRIX NetScaler is currently dealing with CVE-2026-88779, a memory buffer flaw (CWE-119) that has been observed being exploited in the wild against NetScaler SAML authentication deployments using a Gateway or AAA virtual server. Citrix attributes CVSS 4.0 with a score of 8.7 and notes that repeated triggering of the condition can render the affected service unavailable, effectively causing a Denial of Service without impacting data integrity.

The vulnerability affects NetScaler ADC and Gateway installations prior to certain builds and is triggered via specific SAML configuration commands, notably the “add authentication samlAction” or “add authentication samlIdPProfile” entries.

Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, and the corresponding FIPS/NDcPP variants (14.1-73.41 FIPS and 13.1-37.282 NDcPP). Evidence cited by Citrix points to active exploitation in unmitigated deployments, with administrators reporting internet-facing devices rebooting after patching. The practical response is mandatory upgrading to 14.1-73.41, 13.1-64.28, or the matching FIPS/NDcPP builds, even for those who had previously patched for September updates.

While waiting for upgrades, Citrix recommends mitigation using Global Deny List signatures via the NetScaler Console and applying firewall blocks to attacking IPs as an interim measure.

View full article

Article by CyberSIXT