Skip to main content
Emerging Threats

Citrix Disrupts Zero-Day Attacks on NetScaler with Emergency Patches

Technicians in a network operations room examine a laptop near a NetScaler device on a rack.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company wrote in a blog post published with its advisory.

Citrix advisory and emergency patches

Citrix has issued emergency updates to address a newly discovered NetScaler vulnerability tracked as CVE-2026-88779. The company says the flaw is a memory buffer issue that affects NetScaler ADC and NetScaler Gateway appliances when SAML authentication is configured with Gateway or AAA functionality. The advisory gives the vulnerability a CVSS score of 8.7 and says the issue has been used in targeted attacks that cause denial-of-service conditions.

Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway updates 14.1-73.41 and 13.1-64.28 to fix CVE-2026-88779. For FIPS deployments, Citrix directed customers to upgrade to 14.1-73.41 FIPS; NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282. Citrix is also offering Global Deny Lists to block known malicious IP addresses, but it recommends installing the security updates as soon as possible.

Observed exploitation and signs of a zero-day in the wild

Citrix confirmed "targeted attacks on unmitigated NetScaler deployments" and said its engineering and support teams were tracking a "newly observed issue" related to SAML authentication in customer-managed NetScaler environments. The company noted affected configurations contain either an authentication samlAction or authentication samlIdPProfile setting, and advised customers experiencing the issue to contact Citrix support.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and giving federal civilian executive branch (FCEB) agencies until October 7 to mitigate the flaw.

Administrator logs, crash patterns, and possible command execution

Administrators monitoring patched appliances reported unexpected reboots and repeated crashes of nsaaad and the Pitboss process. Early reports surfaced on Thursday, with one NetScaler administrator saying multiple customers running 14.1-73.37 were experiencing forced reboots despite having installed the latest updates available at the time.

One administrator investigating crashes on 14.1-73.37 devices reported seeing crafted authentication usernames that contained shell commands to download a payload from 213.209.159[.]55, save it as /v, and execute it. According to that administrator, these requests appeared immediately before three confirmed nsaaad crash sequences on a single appliance and targeted multiple SAML authentication factors. The administrator stressed that logs showed attempted exploitation and correlated crashes but did not confirm successful execution of the commands.

Honeypots, malware, and independent researcher findings

  • Cybersecurity researcher Kevin Beaumont reported that patched NetScaler 13.1 and 14.1 honeypots were crashing after receiving requests from multiple source IP addresses, calling the activity potentially another "PitScaler" vulnerability. Beaumont later said one of his patched honeypots was running a downloaded malware payload: "So on one of the honeypots it’s running a downloaded (malware) binary. Both were patched, so new vuln."
  • Beaumont added that the activity appeared to go beyond denial-of-service: "It’s being sprayed and prayed. One of the honeypots doesn’t even have a valid SSL certificate as I let it expire."
  • watchTowr Labs also confirmed it reproduced the vulnerability after investigating honeypot activity, though the researchers did not publish technical reproduction details.

What this means for security teams, FCEB agencies, and NetScaler administrators

  • Security teams and NetScaler administrators: Check whether appliances are configured as a SAML service provider (add authentication samlAction) or a SAML identity provider (add authentication samlIdPProfile). If so, prioritize applying the 14.1-73.41 or 13.1-64.28 updates (or the FIPS/NDcPP-specific releases) and consider deploying Citrix's Global Deny Lists as a short-term mitigation.
  • FCEB agencies and regulated customers: CISA’s addition of CVE-2026-88779 to its Known Exploited Vulnerabilities catalog sets an October 7 mitigation deadline for FCEB agencies, requiring rapid verification and patching of affected appliances.
  • Enterprises that recently updated: Citrix warned organizations that upgraded earlier to address CVE-2026-88771 through CVE-2026-88778 must upgrade again if their NetScaler deployments meet the SAML preconditions.

Citrix’s analysis emphasizes impact to service availability and states that it "has not identified an impact on the integrity of customer data." But multiple independent observations — crash sequences, crafted authentication requests containing shell commands, and at least one patched honeypot running a downloaded binary — mean defenders must treat CVE-2026-88779 as actively exploited and potentially more dangerous than its initial denial-of-service label suggests. Agencies, administrators, and security teams have only days to replace interim fixes with the updated releases Citrix published and to validate their appliances are no longer reachable by the activity recorded in public logs.

Original story: https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/