NetScaler ADC and NetScaler Gateway SAML authentication

CVE-2026-88779: SAML memory overflow crashes NetScaler authentication

An unauthenticated attacker can crash the SAML authentication service on NetScaler ADC and Gateway, and repeated attacks keep it offline. Exploited as a zero-day, including against appliances already patched for CVE-2026-88771; added to CISA KEV on October 4, 2026.

Published Updated

ExploitedYes, in CISA KEVAdded 4 Oct 2026
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 4.0 8.7
EPSS0.59%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
NetScaler ADC and Gateway 14.114.1-73.41 or later
NetScaler ADC and Gateway 13.113.1-64.28 or later
NetScaler ADC 14.1 FIPS14.1-73.41 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPP13.1-37.282 or later
Citrix-managed cloud servicesNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A memory overflow in the SAML authentication handler of NetScaler ADC and Gateway. Orca names the nsaaad process. An unauthenticated attacker who can reach the SAML service can crash it. Repeated attacks keep authentication down, which can lock users out of VPN and SSO. Citrix rates it 8.7 (CVSS 4.0) and has found no impact on data integrity.

It was exploited as a zero-day. Administrators first reported fully patched appliances rebooting, including freshly rebuilt 14.1-73.37 images. The nsaaad process crashed repeatedly until NetScaler’s Pitboss process hit its restart limit and rebooted the box (BleepingComputer). Kevin Beaumont saw patched honeypots crash and one run a downloaded binary. watchTowr reproduced the bug and says it can only crash systems.

Citrix calls this denial of service, but remote code execution is not ruled out. Some researchers suspect it, and Beaumont notes Citrix first called CVE-2025-6543 a DoS bug as well. One administrator saw SAML usernames containing shell commands that download and run a payload, right before the crashes. The logs show attempts, not proof that the commands ran. Treat RCE as unconfirmed.

This is the third NetScaler zero-day in about two weeks, after CVE-2026-88771 and CVE-2026-88772. watchTowr suspects crashing appliances may help exploit CVE-2026-88771.

Am I affected?

You’re affected if both are true:

  1. You run a customer-managed NetScaler ADC or Gateway below the fixed builds (see the table above).
  2. The appliance is configured as a SAML service provider or SAML identity provider. Secure Private Access Hybrid deployments that use NetScaler instances meet this condition.

Citrix’s preconditions are these configuration entries (BleepingComputer, Orca):

  • SAML service provider: add authentication samlAction
  • SAML identity provider: add authentication samlIdPProfile

If your configuration has either entry, treat the appliance as exposed.

Already patched for CVE-2026-88771 through CVE-2026-88778? You still need this update if you use SAML. Citrix-managed cloud services are not affected.

What to do

  1. Upgrade now. Move to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 (FIPS and NDcPP on 13.1), or later. This also applies to appliances you patched last week.
  2. If you can’t upgrade tonight, Citrix offers Global Deny Lists that block known malicious IPs. The watchTowr FAQ says the Console’s Virtual patching option applies only to specific intermediate builds. Both are stopgaps. Admins reported in the SecurityWeek coverage that interim workarounds sometimes failed to stop the crashes.
  3. Preserve evidence first if you suspect compromise: logs, support bundle and a snapshot (watchTowr’s response steps).
  4. Run the NetScaler Console IoC script that Citrix points to. It can falsely report suspicious “nobody” processes, and Citrix’s detection script missed compromises in the related CVE-2026-88771 case, so don’t treat a clean result as proof.
  5. If compromise is confirmed, deploy a new instance instead of reusing the appliance (watchTowr), and contact Citrix support. Rotate secrets held on the box as in CVE-2026-88771.

Detection

Search back to at least October 2, 2026, when the first reboots were reported.

  • Unexplained nsaaad crashes, Pitboss restarts and appliance reboots, especially on patched builds.
  • Authentication requests whose username field contains shell commands, particularly ones that download a file and run it (BleepingComputer).
  • Requests that mention 213.209.159[.]55, and a file named /v on the appliance.
  • Outbound connections to the same address.

No other indicators have been published by a source we could open. If you find a downloaded binary or web shell, handle it as a CVE-2026-88771-style compromise and see that page for file paths to check.

Indicators of compromise

These come from one administrator's logs. They show attempted exploitation next to nsaaad crashes, not confirmed command execution. Use them to search past logs, not as a block list.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-88779.txt

IndicatorTypeReported by
213.209.159[.]55IPPayload host named in crafted SAML usernames; the file was saved as /vAn administrator, via BleepingComputer
/vFile pathFile name used by the downloaded payloadAn administrator, via BleepingComputer

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.