Back to Newsroom
Threat Intel

Active Zero-Day in Citrix NetScaler Can Knock Out SAML Logins

Citrix has patched an actively exploited memory-overflow flaw in NetScaler ADC and Gateway that lets attackers trigger denial-of-service on SAML-enabled deployments. CISA has given federal agencies until October 7 to patch.

Active Zero-Day in Citrix NetScaler Can Knock Out SAML Logins

Citrix has shipped emergency patches for a high-severity zero-day in NetScaler ADC and NetScaler Gateway that attackers are already exploiting in targeted attacks, with the flaw capable of taking authentication infrastructure completely offline.

What happened

Tracked as CVE-2026-88779 and rated 8.7 out of 10 on the CVSS scale, the bug is a memory overflow condition that can be triggered remotely under specific configuration conditions, leading to denial-of-service. The exposure is tied to how NetScaler handles SAML authentication: appliances configured as a SAML service provider or identity provider - including Gateway and AAA deployments using SAML - are the ones at risk. Citrix says repeated triggering keeps the service unavailable, though its own analysis so far has found no impact to the integrity of customer data.

Citrix credited security researchers at Bishop Fox and watchTowr with reporting the issue. Fixes are available in NetScaler ADC and Gateway 14.1-73.41 and later, 13.1-64.28 and later (13.1 branch), 14.1-FIPS 14.1-73.41 and later, and 13.1-FIPS/13.1-NDcPP 13.1-37.282 and later.

The disclosure lands on the heels of two other NetScaler CVEs, 88771 and 88772, which were already being used in the wild to drop web shells and tunneling tools on compromised appliances - a reminder that NetScaler gateways have become a recurring target for intrusion sets looking for a durable foothold on the edge.

Why it matters

NetScaler ADC and Gateway sit at the front door of enterprise remote access and SSO, so a DoS here isn't cosmetic: it can lock out legitimate users, break federated logins and SAML-based SSO flows, and create exactly the kind of outage window attackers like to exploit for pretexting or to mask other activity on the network. The flaw already being exploited before a patch existed, combined with CISA adding it to the Known Exploited Vulnerabilities catalog and giving federal agencies until October 7, 2026 to remediate, both point to active, opportunistic scanning for unpatched instances.

What to do

  • Patch NetScaler ADC and NetScaler Gateway to the fixed builds listed above immediately - treat this as emergency-change territory, not routine maintenance.
  • Check whether your deployment is configured as a SAML SP or IdP (add authentication samlAction / add authentication samlIdPProfile) - those are the configurations in scope.
  • If patching can't happen immediately, monitor NetScaler availability and authentication logs for repeated crashes or service restarts that could indicate exploitation attempts.
  • Review NetScaler appliances for signs of the earlier web shell / tunneling activity linked to CVE-2026-88771 and CVE-2026-88772, since these edge devices have been a repeat target this cycle.
  • Prioritize internet-facing and customer-managed NetScaler deployments, which Citrix flags as the ones affected.
SHARE