Vulnerability

SAML-authentication on NetScaler

Citrix is ​​investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA.

Clip path group@2x

T-Update

Information about vulnerabilities

This live blog provides information regarding a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA.

Last blog update on October 4

Update October 4, 2026

Citrix has released a security update for the previously reported issue regarding SAML authentication on NetScaler. The associated security bulletin, CTX697174, describes the vulnerability as a Denial-of-Service (DoS) vulnerability. However, there were indications yesterday of a Remote Code Execution (RCE) vulnerability.
‍

Background
On October 2, 2026, Citrix reported a new issue in NetScaler environments using SAML authentication in conjunction with Gateway or AAA. A NetScaler is affected if the configuration includes `add authentication samlAction` or `add authentication samlIdPProfile`. Citrix has now published an update for this via CTX697174. According to Citrix, the issue is unrelated to the vulnerabilities covered in CTX697096.

Risk
The patch addresses a DoS vulnerability, while it remains unclear whether the potential RCE vulnerability persists; or if there was never an RCE vulnerability to begin with.

Advice
1. Install the latest patch. Update all NetScaler appliances to the version specified in CTX697174.
2. Keep NetScalers disabled. As long as there is uncertainty regarding a potential RCE vulnerability, we advise keeping NetScalers using SAML authentication disconnected from the Internet, even after installing the patch.
3. Secure evidence. Preserve core dumps from `/var/core/`, log files, and a support bundle from any appliances that have crashed or restarted. This data is required to determine retrospectively whether exploitation has occurred.

We are closely monitoring developments and will update this advice as soon as there is more clarity regarding the nature of the vulnerability.

If you have questions about the potential impact on your environment, or if you require assistance assessing your NetScalers or securing evidence, please contact T-CERT.

‍

‍

Update October 3, 2026

Citrix is investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA. Citrix has announced a security bulletin and corresponding updates, but has not yet published a patched version, CVE number, or full analysis. 

‍

‍

Tailored cybersecurity

Background

Citrix is investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA. According to Citrix, this issue is unrelated to the vulnerabilities in bulletin CTX697096, which we previously reported. The problem only occurs with a specific configuration.

Risk

A NetScaler is affected, according to Citrix, if at least one of the following configuration rules is present:

add authentication samlAction

add authentication samlIdPProfile

This applies to both NetScalers acting as a SAML Service Provider and those configured as a SAML Identity Provider. Administrators report that the nsaaad authentication process crashes when processing malformed SAML requests. This can lead to a failover within a high-availability configuration or a restart of the appliance. This also affects systems that have already been updated to 14.1-73.37 or 13.1-64.23.

‍

We consider this a security issue rather than just a stability problem. Exploitation of the vulnerability has already been observed. 

Citrix is publishing this via their security channel and has announced a security bulletin. As long as the root cause remains unknown, we cannot rule out the possibility that the issue could be exploited for more than just crashing the service. Furthermore, a SAML configuration on a Gateway or AAA virtual server is by definition accessible from the internet.

A restart or failover is not a reliable indicator of what has occurred. A crashed process may point to a failed attempt, but it does not rule out a successful one.

‍

Advice

  1. Determine if SAML is configured. Run the following command on every NetScaler:
    show ns runningConfig | grep -i "add authentication saml"
    If this returns a result containing samlAction or samlIdPProfile, the appliance is within the scope of this issue.
    Check all nodes.
    When a Netscaler appliance is within scope:
  1. Secure evidence in the event of a crash or restart. Secure core dumps from /var/core/, log files, and a support bundle before the appliance is restarted or modified. Without this data, it will be impossible to determine the root cause later.
  1. Isolate the vulnerable node from the network, and verify that a currently passive node does not have this configuration.  
  1. Monitor for recurring crashes. Keep an eye on ns.log and your SIEM for alerts regarding nsaaad crashes or restarts, unexpected failovers, and appliance reboots.
  1. Contact Citrix Support if you are currently experiencing issues, in accordance with Citrix's guidance.
  1. Install the patched version as soon as the bulletin is released. Schedule a maintenance window for this now. Follow the Citrix security bulletin for the final list of affected versions and patched builds.

‍

Ellipse 6

Sign up for T-Updates

Receive the latest news about malware or vulnerabilities in your inbox every Wednesday

More than 1,000 organizations have already joined us.

Tesorion uses your data to send the requested information. In addition, your data may be used for commercial follow-up. You can unsubscribe from this at any time via the link in the email. For more information, read our privacy policy.

Ellipse 6