CITRIX NetScaler ADC appliances are reportedly rebooting repeatedly after patches were applied, even on builds 14.1-73.37. Citrix has acknowledged a new issue linked to NetScaler SAML authentication and is preparing a security bulletin and a fix, though no patch had been released at the time of the report. The problems follow the disclosure of two critical flaws, CVE-2026-88771 and CVE-2026-88772, which were previously exploited as zero-days.
Unit 42’s telemetry and a Reddit thread noted exposed NetScaler deployments externally rebooting, including fresh builds with Enhanced ISN Generation enabled. The highest-severity ratings for these flaws are CVSSv4 9.5, with potential remote code execution in the case of CVE-2026-88771 and a memory overflow risk that could enable remote code execution or denial of service for CVE-2026-88772.
Citrix states the renewed issue is tied to SAML configurations and is “configuration dependent,” not described by the CTX697096 advisory. Affected deployments are those using NetScaler SAML authentication, specifically when the commands add authentication samlAction or add authentication samlIdPProfile are present. Citrix recommends reviewing Gateway and AAA configurations for SAML actions, contacting Citrix support if impact is observed, and upgrading once the new security bulletin is released.
In the meantime, versions 14.1-73.37 and 13.1-64.23 (including FIPS variants) remain in place as fixes, with the warning from Unit 42 that remediation may not remove attacker persistence, so organisations should also hunt for web shells and backdoors.