SAML-authentication on NetScaler
Citrix is investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA.

T-Update
This live blog provides information regarding a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA.
Last blog update on October 5
Update October 5, 2026
In our previous update (October 4), we advised keeping NetScalers with SAML authentication disabled as long as there was uncertainty regarding a potential RCE vulnerability. Based on current insights, we are adjusting this advice.
Background
Citrix published the vulnerability as CVE-2026-88779, with a CVSS score of 8.7. This concerns a memory overflow in NetScaler ADC and NetScaler Gateway that is configured as a SAML Service Provider or SAML Identity Provider. Citrix and the NCSC describe the vulnerability as a Denial-of-Service (DoS) vulnerability.
Risk
Previously there were signals that the vulnerability would also be exploited for Remote Code Execution (RCE). Reports in the security community included login attempts using usernames that included shell commands. These signals have now diminished. Our contact with other incident response parties has also not revealed any indications of RCE at this time. For the time being, the vulnerability appears to be limited to a DoS.
On a NetScaler without the patch, an attacker can repeatedly crash the authentication service. This can lead to a failover or restart of the appliance, leaving the service unavailable.
Advice
1. Install the patch before bringing the NetScaler back into service.
Update all affected appliances to version 14.1-73.41, 13.1-64.28, or the specified FIPS versions. For high-availability configurations or clusters, this applies to all nodes.
2. Secure evidence before powering on the NetScaler.
Preserve core dumps from `/var/core/`, log files, and a support bundle from appliances that experienced unexpected crashes or restarts.
3. Check authentication logs.
Look for login attempts using anomalous usernames, such as those containing shell commands. Contact T-CERT before powering on the NetScaler if you encounter suspicious successful logins or have other concerns.
4. Monitor after powering on.
Watch `ns.log` and your SIEM for `nsaaad` crashes or restarts, unexpected failovers, and appliance restarts. Additionally, consider implementing Citrix Global Deny Lists to block known malicious IP addresses.
We continue to monitor developments and will update this advice as necessary.
If you have questions regarding the potential impact on your environment, or require support in safely bringing your NetScalers back into service, please contact T-CERT.
Update October 4, 2026
Citrix has released a security update for the previously reported issue regarding SAML authentication on NetScaler. The associated security bulletin, CTX697174, describes the vulnerability as a Denial-of-Service (DoS) vulnerability. However, there were indications yesterday of a Remote Code Execution (RCE) vulnerability.
Background
On October 2, 2026, Citrix reported a new issue in NetScaler environments using SAML authentication in conjunction with Gateway or AAA. A NetScaler is affected if the configuration includes `add authentication samlAction` or `add authentication samlIdPProfile`. Citrix has now published an update for this via CTX697174. According to Citrix, the issue is unrelated to the vulnerabilities covered in CTX697096.
Risk
The patch addresses a DoS vulnerability, while it remains unclear whether the potential RCE vulnerability persists; or if there was never an RCE vulnerability to begin with.
Advice
1. Install the latest patch. Update all NetScaler appliances to the version specified in CTX697174.
2. Keep NetScalers disabled. As long as there is uncertainty regarding a potential RCE vulnerability, we advise keeping NetScalers using SAML authentication disconnected from the Internet, even after installing the patch.
3. Secure evidence. Preserve core dumps from `/var/core/`, log files, and a support bundle from any appliances that have crashed or restarted. This data is required to determine retrospectively whether exploitation has occurred.
We are closely monitoring developments and will update this advice as soon as there is more clarity regarding the nature of the vulnerability.
If you have questions about the potential impact on your environment, or if you require assistance assessing your NetScalers or securing evidence, please contact T-CERT.
Update October 3, 2026
Citrix is investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA. Citrix has announced a security bulletin and corresponding updates, but has not yet published a patched version, CVE number, or full analysis.
Background
Citrix is investigating a new vulnerability in NetScaler environments that use SAML authentication in combination with Gateway or AAA. According to Citrix, this issue is unrelated to the vulnerabilities in bulletin CTX697096, which we previously reported. The problem only occurs with a specific configuration.
Risk
A NetScaler is affected, according to Citrix, if at least one of the following configuration rules is present:
add authentication samlAction
add authentication samlIdPProfile
This applies to both NetScalers acting as a SAML Service Provider and those configured as a SAML Identity Provider. Administrators report that the nsaaad authentication process crashes when processing malformed SAML requests. This can lead to a failover within a high-availability configuration or a restart of the appliance. This also affects systems that have already been updated to 14.1-73.37 or 13.1-64.23.
We consider this a security issue rather than just a stability problem. Exploitation of the vulnerability has already been observed.
Citrix is publishing this via their security channel and has announced a security bulletin. As long as the root cause remains unknown, we cannot rule out the possibility that the issue could be exploited for more than just crashing the service. Furthermore, a SAML configuration on a Gateway or AAA virtual server is by definition accessible from the internet.
A restart or failover is not a reliable indicator of what has occurred. A crashed process may point to a failed attempt, but it does not rule out a successful one.
Advice
- Determine if SAML is configured. Run the following command on every NetScaler:
show ns runningConfig | grep -i "add authentication saml"
If this returns a result containing samlAction or samlIdPProfile, the appliance is within the scope of this issue.
Check all nodes.
When a Netscaler appliance is within scope:
- Secure evidence in the event of a crash or restart. Secure core dumps from /var/core/, log files, and a support bundle before the appliance is restarted or modified. Without this data, it will be impossible to determine the root cause later.
- Isolate the vulnerable node from the network, and verify that a currently passive node does not have this configuration.
- Monitor for recurring crashes. Keep an eye on ns.log and your SIEM for alerts regarding nsaaad crashes or restarts, unexpected failovers, and appliance reboots.
- Contact Citrix Support if you are currently experiencing issues, in accordance with Citrix's guidance.
- Install the patched version as soon as the bulletin is released. Schedule a maintenance window for this now. Follow the Citrix security bulletin for the final list of affected versions and patched builds.
Sign up to receive T-Updates
Receive the latest vulnerabilities in your email every Wednesday
More than 1,000 organisations have already joined us.
