
Citrix has released emergency updates for CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway appliances that use SAML authentication. Citrix rates it 8.7 on the CVSS scale, describes it as a denial-of-service issue, and says it has seen targeted attacks against unmitigated deployments that can leave the service unavailable if the condition is triggered repeatedly. The company says it has not identified an impact on the integrity of customer data.
Researchers think the flaw may go further. Administrators first reported appliances already updated to 14.1-73.37 repeatedly crashing and rebooting on Thursday. One administrator saw crafted login usernames containing shell commands that fetched a payload from a remote IP address and tried to run it; the logs showed attempts and correlated crashes but did not confirm execution. Researcher Kevin Beaumont reported that one patched honeypot was running a downloaded binary. Citrix confirmed the issue is different from the NetScaler vulnerabilities disclosed earlier, so organizations that just upgraded for CVE-2026-88771 through CVE-2026-88778 need to upgrade again.
How to check if you’re affected
Affected products are NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication, either as a SAML service provider (add authentication samlAction) or as an identity provider (add authentication samlIdPProfile). If neither appears in your configuration, the SAML precondition Citrix describes does not apply.
Fixed versions are NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28. FIPS deployments should move to 14.1-73.41 FIPS, and 13.1 NetScaler ADC FIPS and NDcPP customers should install 13.1-37.282. Citrix is also providing Global Deny Lists that block known malicious IP addresses, but recommends installing the updates as soon as possible. Check authentication logs for unusual usernames containing shell commands, and for repeated crashes of the nsaaad process or unexplained reboots.
