Skip to content

NetScaler Patches a SAML Flaw That CISA Lists as Exploited

NetScaler ADC and Gateway builds before 14.1-73.41 and 13.1-64.28 are open to a SAML-linked denial of service, CVE-2026-88779, now on CISA's exploited list.

NetScaler logo in white lettering on a black background
Credit: NetScaler

NetScaler ADC and NetScaler Gateway appliances that handle SAML logins can be pushed into a denial of service through CVE-2026-88779, a memory overflow flaw that CISA added to its Known Exploited Vulnerabilities catalog on October 4.

Citrix rates the flaw 8.7 on the CVSS v4.0 scale and files it as CWE-119, improper restriction of operations within the bounds of a memory buffer. Only NetScaler appliances set up as a SAML service provider or a SAML identity provider are exposed, and an administrator can look for an add authentication samlAction or add authentication samlIdPProfile entry in the configuration to check. The fixed releases are 14.1-73.41 and later on the 14.1 branch, 13.1-64.28 and later on 13.1, 14.1-73.41 FIPS for the 14.1 FIPS builds, and 13.1-37.282 for 13.1-FIPS and 13.1-NDcPP.

Citrix says it has seen targeted attacks on unmitigated deployments and that repeated triggering can leave the service down. In its own analysis, the company reports no sign of damage to the integrity of customer data, which fits a bug that hits availability. NetScaler customers who already upgraded for the earlier bulletins covering CVE-2026-88771 through CVE-2026-88778 and who meet the SAML preconditions need to upgrade a second time, to the builds released for this one.

The entry in CISA's catalog describes the bug as one that could allow denial of service. It sets an October 7 due date for the required action and carries the agency's forensic triage requirement. CISA lists known ransomware campaign use as unknown.

Citrix also points to Global Deny List signatures delivered through NetScaler Console as a stopgap for builds that sit just below the fixed releases, provided signature version 24 or later is in place. The company says they only reduce exposure while customers plan the upgrade. Cloud services that Citrix manages, including Adaptive Authentication, get the update from Citrix itself, so the work falls on customer-managed appliances and on Secure Private Access Hybrid deployments that run NetScaler instances.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.