Full Report
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Analysis Summary
# Vulnerability: Citrix NetScaler SAML Memory Buffer Flaw
## CVE Details
- **CVE ID**: CVE-2026-88779
- **CVSS Score**: 8.7 (High)
- **CWE**: Memory buffer flaw (Specific CWE not explicitly stated, likely CWE-120 or CWE-122)
## Affected Systems
- **Products**: NetScaler ADC and NetScaler Gateway
- **Versions**:
- 14.1 prior to 14.1-73.41
- 13.1 prior to 13.1-64.28
- 14.1 FIPS prior to 14.1-73.41 FIPS
- 13.1 FIPS prior to 13.1-37.282
- **Configurations**: The vulnerability only affects appliances configured for SAML authentication (Gateway or AAA functionality), specifically if:
- Configured as a SAML SP (`add authentication samlAction`) **OR**
- Configured as a SAML IdP (`add authentication samlIdPProfile`)
## Vulnerability Description
The flaw is a memory buffer vulnerability within the SAML authentication process. While officially categorized by Citrix as a Denial of Service (DoS) issue that causes the `nsaaad` process to crash and leads to repeated appliance reboots via the "Pitboss" process, security researchers have observed evidence of memory corruption that may allow for Remote Code Execution (RCE).
## Exploitation
- **Status**: Exploited in the wild (Zero-day)
- **Complexity**: Low to Medium (Observed being "sprayed" across the internet)
- **Attack Vector**: Network (Remote)
## Impact
- **Confidentiality**: Investigating (Evidence of malware payloads suggests High impact)
- **Integrity**: Investigating (Evidence of unauthorized command execution suggests High impact)
- **Availability**: High (Causes service unavailability and repeated system reboots)
## Remediation
### Patches
Citrix recommends upgrading to the following versions immediately:
- NetScaler ADC / Gateway 14.1-73.41
- NetScaler ADC / Gateway 13.1-64.28
- NetScaler ADC 14.1-73.41 FIPS
- NetScaler ADC 13.1-37.282 FIPS
### Workarounds
- **Global Deny Lists**: Citrix provides Global Deny Lists to block known malicious IP addresses (e.g., 213.209.159[.]55).
- **Note**: If patches cannot be applied immediately, contact Citrix Support for specific guidance regarding SAML configurations.
## Detection
- **Indicators of Compromise (IoC)**:
- Unexpected reboots and `nsaaad` process crashes.
- Malicious IP activity: 213.209.159[.]55.
- Log entries showing crafted authentication usernames containing shell commands (e.g., attempts to download and execute files to `/v`).
- **Detection Methods**:
- Monitor NetScaler logs for repeated `nsaaad` crashes.
- Inspect SAML authentication factor logs for unusual characters or shell syntax in username fields.
## References
- Citrix Security Advisory: hxxps://support[.]citrix[.]com/support-home/kbsearch/article?articleNumber=CTX697174
- Citrix TechZone Blog: hxxps://community[.]citrix[.]com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
- BleepingComputer Article: hxxps://www[.]bleepingcomputer[.]com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/