Citrix NetScaler SAML Zero-Day Triggers CISA Warning

Citrix has released emergency patches for a critical NetScaler ADC and NetScaler Gateway zero-day tracked as CVE-2026-88779 after attackers began exploiting it to knock appliances offline in denial-of-service attacks.[13][15] The memory buffer flaw, present in SAML-enabled deployments, prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the bug to its Known Exploited Vulnerabilities (KEV) catalog and order rapid remediation across federal civilian agencies.[7][15][10] CISA warns that exploited vulnerabilities of this type pose significant risks to the federal enterprise, particularly when they underpin remote access services.[14][7]

According to Citrix’s advisory, CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider with Gateway or AAA functionality.[2][13][15] Specially crafted SAML authentication traffic can trigger a memory overflow in the packet processing engine, causing the affected virtual server to crash and disrupting user sessions.[13][15] If attackers repeatedly exploit the condition, the service may remain unavailable, resulting in prolonged outages for VPN, single sign-on, or application delivery services fronted by NetScaler.[13]

The National Vulnerability Database lists impacted NetScaler ADC versions as those prior to 14.1-73.41 and 13.1-64.28, including corresponding FIPS and NDcPP builds, with NetScaler Gateway similarly affected before 14.1-73.41 and 13.1-64.28.[2] CVE-2026-88779 carries a CVSS v3.1 base score of 8.7, reflecting its high potential to cause service disruption to internet-facing authentication and access gateways.[15][2] Citrix notes that targeted attacks have already hit unmitigated NetScaler deployments, corroborating CISA’s decision to treat the flaw as a known exploited vulnerability rather than a purely theoretical risk.[13][7]

CISA added CVE-2026-88779 to the KEV catalog on October 4, 2026 and set an October 7 deadline for federal civilian executive branch agencies to apply vendor patches or otherwise mitigate the exposure.[7][15] Under Binding Operational Directive 22-01, agencies must prioritize remediation of KEV-listed bugs because they represent a frequent attack vector and carry significant risk to the federal enterprise.[14] KEV entries for NetScaler memory overflow issues, including CVE-2026-8452 and CVE-2026-8655, underscore how mismanaged buffer operations in these appliances have become a recurring focus for threat actors and defenders alike.[3][4][10]

The new SAML zero-day lands weeks after disclosure of another critical NetScaler flaw, CVE-2026-88772, a Datagram Transport Layer Security (DTLS) memory overflow vulnerability with a CVSS score of 9.5 that can enable remote code execution or denial of service in certain configurations.[11][5][9] Researchers and Citrix are still investigating whether CVE-2026-88779 can similarly be pushed beyond denial-of-service into remote code execution scenarios, but no such exploitation has been confirmed publicly to date.[13][15] In combination, the recent chain of buffer overflow and memory handling bugs has turned NetScaler appliances into high-value targets for both financially motivated and espionage-focused attackers that seek reliable ways to disrupt or infiltrate remote access infrastructure.[11][12][5]

Organizations running NetScaler ADC or Gateway with SAML, Gateway, or AAA functionality should inventory internet-facing instances and upgrade to the fixed builds specified by Citrix as soon as possible, prioritizing appliances that expose remote access or identity services.[2][13][15] Security teams are advised to monitor for sudden spikes in authentication failures, unexpected appliance reboots, and customer reports of intermittent access issues that may indicate active exploitation of CVE-2026-88779.[13][7] Checking CISA’s KEV catalog, reviewing Citrix’s guidance, and aligning patch schedules with BOD 22-01 prioritization can help defenders reduce the window in which NetScaler zero-day bugs can be used to degrade or compromise critical services.[14][7][10]

References

  1. nvd.nist.gov ยท vuln ยท detailNVD-CVE-2026-88779
  2. CVE-2026-8655 – National Vulnerability Database
  3. NVD-CVE-2026-8452 – NIST
  4. U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
  5. CISA Warns of Citrix NetScaler Flaw Actively Exploited in Attacks
  6. CISA KEV: NetScaler CVE-2026-88771 and CVE-2026-88772 Require …
  7. KEV Entry: CVE-2026-8452 – Vulnerability-Lookup
  8. Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth …
  9. CISA Says Attackers Are Exploiting Two Critical Citrix …
  10. Exploitation of Citrix NetScaler Zero-Day Hits Appliances …
  11. CISA Adds One Known Exploited Vulnerability to Catalog
  12. Citrix patches NetScaler SAML zero-day exploited in attacks

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply