Cyber Security News

Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks

Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.

This flaw, tracked as CVE-2026-88779, could allow unauthenticated remote attackers to cause persistent denial-of-service conditions.

The vulnerability specifically affects appliances configured for SAML authentication, whether set as a Service Provider (SP) or an Identity Provider (IdP).

Cloud Software Group has assigned a CVSS v4 base score of 8.7 to this issue and categorized it as CWE-119, which refers to improper restriction of operations within the bounds of a memory buffer.

The published vector indicates that this flaw can be exploited over the network with low attack complexity and does not require authentication or user interaction. Its assessed impact is primarily on availability.

Citrix NetScaler SAML Vulnerability

CVE-2026-88779 is relevant only when NetScaler ADC or Gateway is set up to process SAML authentication. Citrix specifies that an appliance meets the vulnerability precondition if its configuration includes either of the following entries:

  • `add authentication samlAction` (indicating a SAML SP configuration)
  • `add authentication samlIdPProfile` (indicating a SAML IdP deployment)

Organizations utilizing NetScaler Gateway or AAA functions for federated authentication should prioritize patching any externally reachable SAML-enabled appliances.

This memory overflow issue can cause a device or service to crash. If triggered repeatedly, it may disrupt remote-access portals, identity flows, and applications that rely on the NetScaler appliance for authentication and traffic delivery.

Affected Versions and Fixes

Citrix identifies the following vulnerable product branches:

Product branchVulnerable beforeFixed release
NetScaler ADC and Gateway 14.114.1-73.4114.1-73.41 or later
NetScaler ADC and Gateway 13.113.1-64.2813.1-64.28 or later
NetScaler ADC 14.1-FIPS14.1-73.41 FIPS14.1-73.41 FIPS or later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1-37.28213.1-37.282 or later

Citrix strongly urges affected customers to install the appropriate fixed build as soon as possible. NetScaler Console users can identify impacted instances through its CVE Detection workflow and initiate an upgrade from the affected instance view.

The vulnerability has been reported to be exploited in targeted attacks against unmitigated deployments. While Citrix assesses that the flaw primarily affects availability and does not compromise customer data integrity, widespread gateway disruptions can have significant operational impacts, especially for organizations relying on NetScaler for VPN, workforce access, and SSO services.

Teams should also review appliance crash events, unexpected reboots, SAML-related authentication failures, nsaaad service behavior, firewall telemetry, and identity-provider logs for signs of attempted exploitation.

Finally, Citrix acknowledges Bishop Fox and watchTowr’s collaboration in addressing this issue.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago