Citrix has released emergency patches for a NetScaler vulnerability that is being exploited in zero-day attacks, the company said. The flaw, tracked as CVE-2026-88779, is a memory buffer issue affecting NetScaler ADC and NetScaler Gateway appliances that use SAML authentication with Gateway or AAA functionality. Citrix assigned the vulnerability a CVSS score of 8.7 and said it has been used in targeted attacks against unmitigated deployments, resulting in denial-of-service conditions. The company said its analysis indicates the issue affects service availability and that it has not identified an impact on the integrity of customer data.
The updates, released early Sunday morning, are NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28. Customers running FIPS deployments should upgrade to 14.1-73.41 FIPS, while NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282. Citrix is also providing Global Deny Lists that block access from known malicious IP addresses, though it recommends installing the new security updates as soon as possible. Organizations can check whether their appliances are vulnerable by determining if SAML authentication is configured.
Citrix warned that organizations which recently upgraded NetScaler devices to fix two other actively exploited vulnerabilities must upgrade again. The company said customers who applied releases identified in a security bulletin for CVE-2026-88771 through CVE-2026-88778, and whose deployments meet the preconditions for SAML authentication, should upgrade their deployments once more.
Although Citrix describes CVE-2026-88779 as a denial-of-service vulnerability, NetScaler administrators and cybersecurity researchers have observed activity suggesting it could be used for remote code execution. The attacks were first reported on Thursday, after administrators said recently patched appliances were unexpectedly rebooting. On Reddit, one administrator said multiple customers running NetScaler 14.1-73.37 saw repeated forced reboots despite having installed the latest available security updates. Other administrators reported similar behavior, including on appliances rebuilt from fresh images, and another thread said the nsaaad process crashed repeatedly until NetScaler's Pitboss process hit its restart limit and rebooted the appliance.
One administrator investigating incidents on NetScaler 14.1-73.37 devices found crafted authentication usernames containing shell commands that downloaded a payload from the IP address 213.209.159[.]55, saved it as /v, and executed the file. According to that administrator, the requests appeared immediately before three confirmed nsaaad crash sequences on one appliance and targeted multiple SAML authentication factors. The administrator stressed that the logs showed attempted exploitation and correlated crashes but did not confirm the commands were successfully executed. Other administrators reported the same nsaaad and Pitboss crash patterns, including on systems already upgraded to version 14.1-73.37.
As the investigations continued, Citrix published a security notice on Friday saying its engineering and support teams were tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. Citrix said affected configurations contain either an authentication samlAction or authentication samlIdPProfile setting, and advised customers experiencing the issue to contact support. The company also confirmed the issue was distinct from the previously disclosed NetScaler vulnerabilities. Cybersecurity expert Kevin Beaumont separately reported that patched NetScaler 13.1 and 14.1 honeypots were crashing after receiving requests from multiple source IP addresses, describing the activity as potentially another PitScaler vulnerability.
More cybersecurity news from TechManNews.






