Citrix NetScaler ADC, Gateway Critical SAML Auth Bypass Actively Exploited CVE-2023-3519
Key Takeaways A critical zero-day vulnerability (CVE-2026-88779) in Citrix NetScaler ADC and Gateway appliances is under active exploitation. The flaw, a SAML authentication bypass, can lead to...
Key Takeaways
- A critical zero-day vulnerability (CVE-2026-88779) in Citrix NetScaler ADC and Gateway appliances is under active exploitation.
- The flaw, a SAML authentication bypass, can lead to denial-of-service, disrupting critical services.
- Affected systems include customer-managed appliances configured as SAML service or identity providers.
- Emergency security updates have been released, and immediate patching is strongly advised, even for recently updated systems.
Citrix has issued urgent security updates to address a zero-day vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, identified as CVE-2026-88779, is actively being exploited by threat actors, primarily leading to denial-of-service (DoS) conditions on affected customer-managed appliances.
Table Of Content
The vulnerability specifically targets systems configured as either a SAML service provider or an identity provider. With a CVSS v4.0 score of 8.7, this critical issue stems from a memory overflow (CWE-119), where software fails to properly manage memory boundaries, potentially causing system instability.
Citrix has confirmed that unmitigated deployments are facing targeted attacks. Repeated exploitation of this vulnerability can render essential services unavailable. While Citrix’s analysis confirms an impact on service availability, it has not identified any compromise of customer data integrity, underscoring the DoS nature of the confirmed exploitation.
The CVSS vector highlights the ease of exploitation: attackers can leverage this flaw over a network without requiring any login credentials or user interaction. Its low attack complexity makes any exposed appliance with the requisite SAML configuration a prime target for immediate updates.
Reports of operational issues emerged as administrators observed recently patched appliances repeatedly rebooting. This follows a pattern from previous NetScaler zero-day patches, where crafted SAML traffic could crash the nsaaad authentication service. Some affected systems were found to be running build 14.1-73.37, indicating that prior updates did not mitigate this specific vulnerability.
Investigators also documented authentication requests containing shell commands, seemingly designed to download and execute malicious payloads. These suspicious requests were observed prior to confirmed system crashes, though successful execution of these commands could not be definitively established by the examining administrator.
Adding to the concern, security researcher Kevin Beaumont reported a malware binary running on a patched honeypot, while watchTowr claimed to have successfully reproduced the vulnerability. These findings raise questions about potential code execution capabilities, though it is crucial to differentiate these observations from Citrix’s official classification of CVE-2026-88779 as a denial-of-service flaw.
Affected Versions and Configuration Checks
Citrix’s security bulletin provides a comprehensive list of vulnerable versions. This includes NetScaler ADC and Gateway 14.1 releases prior to 14.1-73.41, and 13.1 releases before 13.1-64.28. NetScaler ADC FIPS releases preceding 14.1-73.41 FIPS are also vulnerable, as are NetScaler ADC FIPS and NDcPP releases before 13.1-37.282.
Organizations utilizing Secure Private Access Hybrid deployments that incorporate these vulnerable NetScaler instances must also apply updates. It is important to note that this advisory pertains to customer-managed systems; Citrix-managed cloud services and Adaptive Authentication instances are updated directly by Cloud Software Group.
Administrators can ascertain potential exposure by checking their configurations for either add authentication samlAction, which denotes a SAML service provider, or add authentication samlIdPProfile, indicating a SAML identity provider. The presence of either of these configurations on an affected build signifies potential vulnerability, though it does not confirm a compromise.
Customers are advised to upgrade to version 14.1-73.41 or later for the 14.1 branch, or 13.1-64.28 or later for the 13.1 branch. FIPS customers should install 14.1-73.41 FIPS or newer, while 13.1 FIPS and NDcPP deployments require 13.1-37.282 or later within their respective branches.
Even organizations that have recently applied previous NetScaler security updates must update again if their systems meet the conditions for this new vulnerability. While Citrix is providing Global Deny Lists to block known malicious IP addresses, prompt patching remains the most critical mitigation. Citrix’s advisory credits Bishop Fox and watchTowr for their assistance in protecting customers.
What You Should Do
- Immediately identify all NetScaler ADC and Gateway appliances configured as SAML service or identity providers.
- Verify the version of all identified appliances against the list of affected versions in the Citrix’s security bulletin.
- Apply the recommended emergency security updates (14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, 13.1-37.282 or later) as soon as possible.
- Even if your systems were recently patched for other vulnerabilities, re-patching for this specific CVE is crucial if your configuration is affected.
- Monitor your NetScaler appliances for unusual activity, repeated reboots, or signs of compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.