Particle.news

Citrix Issues Emergency Patch for Actively Exploited NetScaler SAML Flaw

Observed appliance crashes with signs of malware execution have prompted Citrix to issue emergency updates.

Overview

  • Citrix released emergency NetScaler builds to fix CVE-2026-88779 and CISA added the flaw to its Known Exploited Vulnerabilities list with federal agencies ordered to mitigate by Oct. 7.
  • The bug is a memory overflow in SAML handling that affects NetScaler ADC and NetScaler Gateway instances configured as a SAML service provider or identity provider and can cause service outages.
  • Administrators and researchers have recorded repeated nsaaad and Pitboss crashes, authentication requests with crafted SAML usernames that include shell commands, and at least one patched honeypot running a downloaded binary.
  • Citrix is providing Global Deny Lists and guidance to check SAML settings and it urges customers to install the new updates right away and to re-upgrade systems that were patched for earlier NetScaler fixes.
  • Because NetScaler appliances are widely deployed and prior NetScaler zero-days have led to web shells and tunneling tools, defenders are advised to preserve memory and logs, rotate keys and credentials, and watch for follow-on access after initial compromise.