securityonline.info 2 Oct 2026, 21:32 UTC

Citrix NetScaler Reboots Persist as SAML Flaw Fix Remains Pending

Citrix NetScaler Reboots Persist as SAML Flaw Fix Remains Pending
CyberSIXT Evidence Panel Source marked as original reporting

CITRIX NetScaler ADC appliances are reportedly rebooting repeatedly after patches were applied, even on builds 14.1-73.37. Citrix has acknowledged a new issue linked to NetScaler SAML authentication and is preparing a security bulletin and a fix, though no patch had been released at the time of the report. The problems follow the disclosure of two critical flaws, CVE-2026-88771 and CVE-2026-88772, which were previously exploited as zero-days.

Unit 42’s telemetry and a Reddit thread noted exposed NetScaler deployments externally rebooting, including fresh builds with Enhanced ISN Generation enabled. The highest-severity ratings for these flaws are CVSSv4 9.5, with potential remote code execution in the case of CVE-2026-88771 and a memory overflow risk that could enable remote code execution or denial of service for CVE-2026-88772.

Citrix states the renewed issue is tied to SAML configurations and is “configuration dependent,” not described by the CTX697096 advisory. Affected deployments are those using NetScaler SAML authentication, specifically when the commands add authentication samlAction or add authentication samlIdPProfile are present. Citrix recommends reviewing Gateway and AAA configurations for SAML actions, contacting Citrix support if impact is observed, and upgrading once the new security bulletin is released.

In the meantime, versions 14.1-73.37 and 13.1-64.23 (including FIPS variants) remain in place as fixes, with the warning from Unit 42 that remediation may not remove attacker persistence, so organisations should also hunt for web shells and backdoors.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline