RC RANDOM CHAOS

Citrix patches second NetScaler SAML bug in days

Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.

· 3 min read
Citrix patches second NetScaler SAML bug in days

Citrix shipped NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 early Sunday to close CVE-2026-88779, a memory overflow bug it rates CVSS 8.7 and classifies as denial-of-service. Citrix describes the attacks as hitting unmitigated deployments, but administrators reported appliances already running 14.1-73.37, the build released days earlier to fix CVE-2026-88771 through 88778, getting hit regardless. If you patched that round and your deployment uses SAML, you patch again.

The precondition is narrow. The flaw only applies when NetScaler is configured as a SAML service provider or identity provider, with Gateway or AAA functionality in play. You can check for it directly: add authentication samlAction means you are acting as an SP, add authentication samlIdPProfile means IdP. Either one and you meet the condition.

What administrators actually observed started on Friday as unexplained reboots. Multiple shops running 14.1-73.37, the latest firmware at the time, reported appliances rebooting on their own, including boxes rebuilt from fresh images. The mechanism: the nsaaad authentication daemon crashing repeatedly until the Pitboss supervisor hit its restart limit and bounced the whole appliance. Citrix’s own description matches the symptom. Trigger the condition often enough and the service stays down.

Then it stopped looking like plain denial-of-service. One admin investigating the crashes on 14.1-73.37 found crafted authentication usernames carrying shell commands: download a payload from 213.209.159[.]55, save it as /v, execute it. Those requests landed immediately before three confirmed nsaaad crash sequences on one appliance and hit multiple SAML authentication factors. The admin was careful to say the logs showed attempted exploitation and correlated crashes, not confirmed execution.

Kevin Beaumont saw the same pattern on patched 13.1 and 14.1 honeypots and initially called it another “PitScaler” DoS. He revised that after one of his patched honeypots ran a downloaded binary. “So on one of the honeypots it’s running a downloaded (malware) binary. Both were patched, so new vuln,” he wrote, adding that the activity was being sprayed indiscriminately. One honeypot did not even have a valid certificate, which did not stop it getting hit. watchTowr Labs says it reproduced the vulnerability within hours of spotting the honeypot activity, though it has not published technical details. Citrix credits Bishop Fox and watchTowr for the report.

The DoS label deserves skepticism for a specific reason. Beaumont points out that CVE-2025-6543 was first characterized the same way, a memory overflow leading to denial-of-service, before later attacks showed it could run code. Citrix maintains that CVE-2026-88779 affects availability only and that it has found no impact on data integrity. Researchers are still investigating whether it reaches remote code execution.

Separately, Citrix and others report active exploitation of CVE-2026-88771 and CVE-2026-88772 to drop web shells and tunneling tools on compromised appliances. That is persistence on an edge device that terminates your VPN and sits in front of internal apps. Patching the DoS bug does nothing for a box that was already shelled through a different flaw, so an upgrade is not an all-clear. If any of these appliances were exposed and unpatched during the window, assume they need forensic review, not just a version bump.

For the immediate work: upgrade to 14.1-73.41 or 13.1-64.28. FIPS deployments go to 14.1-73.41 FIPS; FIPS and NDcPP on the 13.1 branch go to 13.1-37.282. Citrix is publishing Global Deny Lists of known malicious IPs, which buys time but is not a fix given Beaumont’s note that the attacks are untargeted and widespread. CISA added CVE-2026-88779 to its KEV catalog on Sunday and set an October 7 deadline for federal civilian agencies.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.