Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Are there road signs in Japan warning drivers that cats may jump out into traffic?

    October 5, 2026

    Manchester City must be relegated, says Canada’s ex-Leeds manager | Football

    October 5, 2026

    This toolless modular lever-action wallet is the coolest I’ve stuck to my phone

    October 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Are there road signs in Japan warning drivers that cats may jump out into traffic?
    • Manchester City must be relegated, says Canada’s ex-Leeds manager | Football
    • This toolless modular lever-action wallet is the coolest I’ve stuck to my phone
    • Citrix patches NetScaler SAML zero-day exploited in attacks
    • Bitcoin recovery awaits ETF demand after payrolls
    • This common vitamin could help fight one of the deadliest brain cancers
    • Parental alienation and the pain of custody battles in the the family courts | Child protection
    • US withdraws all B-1 bombers from British military base RAF Fairford
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Citrix patches NetScaler SAML zero-day exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 4, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.

    The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality.

    The Citrix security advisory says the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial-of-service conditions.

    “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix said in a related blog post published today.

    “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

    Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix the CVE-2026-88779 zero-day flaw.

    For FIPS deployments, customers should upgrade to 14.1-73.41 FIPS. NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282.

    Citrix is also providing Global Deny Lists that will block access from known malicious IP addresses. However, the company recommends that customers install the newly released security updates as soon as possible.

    The company says organizations can determine if their appliances are vulnerable to the flaw by checking whether SAML authentication is configured:

    • Appliance is configured as a SAML SP 
      add authentication samlAction

      OR

       

    • Appliance is configured as a SAML IdP 
      add authentication samlIdPProfile

    Unfortunately, organizations that recently upgraded NetScaler devices to fix two actively exploited vulnerabilities must upgrade them again to fix this flaw.

    “If you upgraded your NetScaler deployment with one of the updated software releases identified in the security bulletin for CVE 2026-88771 through CVE 2026-88778, and if you have determined that your NetScaler deployment meets the preconditions describe above, please upgrade your deployment again,” Citrix warned.

    Researchers investigate possible code execution

    While Citrix describes CVE-2026-88779 as a denial-of-service vulnerability, NetScaler administrators and cybersecurity researchers have seen activity that indicates the flaw can be used for remote code execution.

    The new attacks were first reported on Thursday after NetScaler administrators reported that recently patched appliances were unexpectedly rebooting.

    In a Reddit thread, one NetScaler admin said multiple customers running NetScaler 14.1-73.37 were experiencing repeated forced reboots despite having installed the latest security updates available at the time.

    Other administrators quickly reported similar behavior, including on appliances rebuilt from fresh images. Another Reddit thread said nsaaad was repeatedly crashing until NetScaler’s Pitboss process reached its restart limit and rebooted the appliance.

    At first, it was unclear whether vulnerability scanners were triggering a bug in recently released firmware or whether attackers were actively exploiting new flaws in NetScaler devices.

    However, one administrator investigating these incidents on NetScaler 14.1-73.37 devices saw crafted authentication usernames containing shell commands that download a payload from the IP address 213.209.159[.]55, save it as /v, and execute the file.

    According to the administrator, these requests appeared immediately before three confirmed nsaaad crash sequences on one appliance and targeted multiple SAML authentication factors.

    The administrator stressed that the logs showed attempted exploitation and correlated crashes but did not confirm that the commands were successfully executed.

    Other administrators reported the same nsaaad and Pitboss crash patterns, including on systems already upgraded to version 14.1-73.37.

    As administrators continued investigating the crashes, Citrix published a security notice on Friday saying its engineering and support teams were tracking a “newly observed issue” related to SAML authentication in customer-managed NetScaler deployments.

    The company said affected configurations contain either an authentication samlAction or authentication samlIdPProfile setting and advised customers experiencing the issue to contact Citrix support.

    Citrix also confirmed that the issue was different from the previously disclosed NetScaler vulnerabilities.

    Cybersecurity expert Kevin Beaumont also reported that patched NetScaler 13.1 and 14.1 honeypots were crashing after receiving requests from multiple source IP addresses, describing the activity as potentially another “PitScaler” vulnerability.

    He later said the activity appeared to go further than just denial-of-service, after finding that one of his patched honeypots was running a downloaded malware payload.

    “So on one of the honeypots it’s running a downloaded (malware) binary. Both were patched, so new vuln,” Beaumont said.

    “It’s being sprayed and prayed. One of the honeypots doesn’t even have a valid SSL certificate as I let it expire.”

    Beaumont also said that CVE-2026-88779 was described as a “Memory overflow vulnerability leading to Denial of Service,” similar to how the previously disclosed CVE-2025-6543 was initially characterized before later attacks showed it could be used for remote code execution.

    Cybersecurity company watchTowr Labs also confirmed that it reproduced the vulnerability after initially investigating reports of NetScaler honeypot activity.

    The researchers have not yet disclosed technical details about how they reproduced the flaw.

    On Sunday, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming the flaw is being actively exploited and giving FCEB agencies until October 7 to mitigate it.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks Citrix Exploited NetScaler Patches SAML ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    Anthropic asks Claude users to share voice data for AI model training

    China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

    ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

    Google Gemini could soon get full access to your Mac’s files, apps and the web

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Are there road signs in Japan warning drivers that cats may jump out into traffic?

    October 5, 2026

    Manchester City must be relegated, says Canada’s ex-Leeds manager | Football

    October 5, 2026

    This toolless modular lever-action wallet is the coolest I’ve stuck to my phone

    October 4, 2026

    Citrix patches NetScaler SAML zero-day exploited in attacks

    October 4, 2026
    Latest Posts

    Bald Range Wildfire Forces Evacuation of 18,000 in British Columbia

    August 9, 2026

    Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Are there road signs in Japan warning drivers that cats may jump out into traffic?

    October 5, 2026

    Manchester City must be relegated, says Canada’s ex-Leeds manager | Football

    October 5, 2026

    This toolless modular lever-action wallet is the coolest I’ve stuck to my phone

    October 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.