New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.
The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.
"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."

For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following -
SAML SP - add authentication samlAction
SAML IdP - add authentication samlIdPProfile
The issue has been addressed in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability. In a post shared on X, watchTowr said it has been able to reproduce the security flaw within hours of detecting NetScaler honeypot activity.
"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service," the company acknowledged. "If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."
The patches come after Citrix said it's tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it's related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.
The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.
Some measures we should take to protect against these types of attacks include:
Apply Patches: Immediately upgrade to the latest versions released by Citrix (14.1-73.41, 13.1-64.28, and higher).
Check SAML Configuration: Identify devices with samlAction or samlIdPProfile defined and prioritize their updates.
Enable WAF Rules: Activate Web Application Firewall rules to block abnormal and malformed SAML requests.
Restrict Management Interfaces: Close NSIP/SNIP management access to the external internet and apply IP restrictions.
Perform Web Shell Scans: Check the device for unauthorized files, web shells, and tunneling tools.
Enhance Logging and SIEM Monitoring: Set up SIEM alerts to capture service crashes and suspicious SAML traffic.
For detailed information, you can contact our experts at info@zerosecond.ae





















Comments