Citrix patches second NetScaler SAML bug in days
Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.
Citrix shipped NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 early Sunday to close CVE-2026-88779, a memory overflow bug it rates CVSS 8.7 and classifies as denial-of-service. Citrix describes the attacks as hitting unmitigated deployments, but administrators reported appliances already running 14.1-73.37, the build released days earlier to fix CVE-2026-88771 through 88778, getting hit regardless. If you patched that round and your deployment uses SAML, you patch again.
The precondition is narrow. The flaw only applies when NetScaler is configured as a SAML service provider or identity provider, with Gateway or AAA functionality in play. You can check for it directly: add authentication samlAction means you are acting as an SP, add authentication samlIdPProfile means IdP. Either one and you meet the condition.
What administrators actually observed started on Friday as unexplained reboots. Multiple shops running 14.1-73.37, the latest firmware at the time, reported appliances rebooting on their own, including boxes rebuilt from fresh images. The mechanism: the nsaaad authentication daemon crashing repeatedly until the Pitboss supervisor hit its restart limit and bounced the whole appliance. Citrix’s own description matches the symptom. Trigger the condition often enough and the service stays down.
Then it stopped looking like plain denial-of-service. One admin investigating the crashes on 14.1-73.37 found crafted authentication usernames carrying shell commands: download a payload from 213.209.159[.]55, save it as /v, execute it. Those requests landed immediately before three confirmed nsaaad crash sequences on one appliance and hit multiple SAML authentication factors. The admin was careful to say the logs showed attempted exploitation and correlated crashes, not confirmed execution.
Kevin Beaumont saw the same pattern on patched 13.1 and 14.1 honeypots and initially called it another “PitScaler” DoS. He revised that after one of his patched honeypots ran a downloaded binary. “So on one of the honeypots it’s running a downloaded (malware) binary. Both were patched, so new vuln,” he wrote, adding that the activity was being sprayed indiscriminately. One honeypot did not even have a valid certificate, which did not stop it getting hit. watchTowr Labs says it reproduced the vulnerability within hours of spotting the honeypot activity, though it has not published technical details. Citrix credits Bishop Fox and watchTowr for the report.
The DoS label deserves skepticism for a specific reason. Beaumont points out that CVE-2025-6543 was first characterized the same way, a memory overflow leading to denial-of-service, before later attacks showed it could run code. Citrix maintains that CVE-2026-88779 affects availability only and that it has found no impact on data integrity. Researchers are still investigating whether it reaches remote code execution.
Separately, Citrix and others report active exploitation of CVE-2026-88771 and CVE-2026-88772 to drop web shells and tunneling tools on compromised appliances. That is persistence on an edge device that terminates your VPN and sits in front of internal apps. Patching the DoS bug does nothing for a box that was already shelled through a different flaw, so an upgrade is not an all-clear. If any of these appliances were exposed and unpatched during the window, assume they need forensic review, not just a version bump.
For the immediate work: upgrade to 14.1-73.41 or 13.1-64.28. FIPS deployments go to 14.1-73.41 FIPS; FIPS and NDcPP on the 13.1 branch go to 13.1-37.282. Citrix is publishing Global Deny Lists of known malicious IPs, which buys time but is not a fix given Beaumont’s note that the attacks are untargeted and widespread. CISA added CVE-2026-88779 to its KEV catalog on Sunday and set an October 7 deadline for federal civilian agencies.
Keep Reading
cryptocurrencyAttackers drained $387.5M through Bitget's own security appliances
Bitget confirms a third-party zero-day let attackers reach its wallet job server and drain $387.5M; SlowMist and Mandiant trace the two-stage path.
appleiOS CoreGraphics PoC published two days after the patch
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics triggered by a malicious PDF font and used in targeted attacks on iOS before 27.
zammadTwo Zammad zero-days let an AI agent reach root
DIVD says two Zammad zero-days let an AI agent hijack a session, reach root, and exfiltrate data in seconds; network segmentation limited the breach.
Latest on the Wire
Full wire →- 16 Fake Firefox Extensions Stole Crypto Recovery PhrasesThe Hacker News
- AI Bolsters and Threatens Autocratic RegimesSchneier on Security
- AI Developer Launches Open-Source Adobe AlternativesArs Technica
- AI Helps Solve 15-Year Mystery of Obscure Band SalvageHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.