Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Certificate Lifecycle Management Tools for 2026
October 5, 2026
Cling Malware Disguised as Google STUN Traffic Controls IoT Devices
October 5, 2026
Top Fine-Grained Authorization Tools for 2026
October 5, 2026
Home/CyberSecurity News/Citrix NetScaler ADC, Gateway Critical SAML Auth Bypass Actively Exploited CVE-2023-3519
CyberSecurity News

Citrix NetScaler ADC, Gateway Critical SAML Auth Bypass Actively Exploited CVE-2023-3519

Key Takeaways A critical zero-day vulnerability (CVE-2026-88779) in Citrix NetScaler ADC and Gateway appliances is under active exploitation. The flaw, a SAML authentication bypass, can lead to...

Emy Elsamnoudy
Emy Elsamnoudy
October 5, 2026 3 Min Read
2 0

Key Takeaways

  • A critical zero-day vulnerability (CVE-2026-88779) in Citrix NetScaler ADC and Gateway appliances is under active exploitation.
  • The flaw, a SAML authentication bypass, can lead to denial-of-service, disrupting critical services.
  • Affected systems include customer-managed appliances configured as SAML service or identity providers.
  • Emergency security updates have been released, and immediate patching is strongly advised, even for recently updated systems.

Citrix has issued urgent security updates to address a zero-day vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, identified as CVE-2026-88779, is actively being exploited by threat actors, primarily leading to denial-of-service (DoS) conditions on affected customer-managed appliances.

Table Of Content

  • Key Takeaways
  • Affected Versions and Configuration Checks
  • What You Should Do

The vulnerability specifically targets systems configured as either a SAML service provider or an identity provider. With a CVSS v4.0 score of 8.7, this critical issue stems from a memory overflow (CWE-119), where software fails to properly manage memory boundaries, potentially causing system instability.

Citrix has confirmed that unmitigated deployments are facing targeted attacks. Repeated exploitation of this vulnerability can render essential services unavailable. While Citrix’s analysis confirms an impact on service availability, it has not identified any compromise of customer data integrity, underscoring the DoS nature of the confirmed exploitation.

The CVSS vector highlights the ease of exploitation: attackers can leverage this flaw over a network without requiring any login credentials or user interaction. Its low attack complexity makes any exposed appliance with the requisite SAML configuration a prime target for immediate updates.

Reports of operational issues emerged as administrators observed recently patched appliances repeatedly rebooting. This follows a pattern from previous NetScaler zero-day patches, where crafted SAML traffic could crash the nsaaad authentication service. Some affected systems were found to be running build 14.1-73.37, indicating that prior updates did not mitigate this specific vulnerability.

Investigators also documented authentication requests containing shell commands, seemingly designed to download and execute malicious payloads. These suspicious requests were observed prior to confirmed system crashes, though successful execution of these commands could not be definitively established by the examining administrator.

Adding to the concern, security researcher Kevin Beaumont reported a malware binary running on a patched honeypot, while watchTowr claimed to have successfully reproduced the vulnerability. These findings raise questions about potential code execution capabilities, though it is crucial to differentiate these observations from Citrix’s official classification of CVE-2026-88779 as a denial-of-service flaw.

Affected Versions and Configuration Checks

Citrix’s security bulletin provides a comprehensive list of vulnerable versions. This includes NetScaler ADC and Gateway 14.1 releases prior to 14.1-73.41, and 13.1 releases before 13.1-64.28. NetScaler ADC FIPS releases preceding 14.1-73.41 FIPS are also vulnerable, as are NetScaler ADC FIPS and NDcPP releases before 13.1-37.282.

Organizations utilizing Secure Private Access Hybrid deployments that incorporate these vulnerable NetScaler instances must also apply updates. It is important to note that this advisory pertains to customer-managed systems; Citrix-managed cloud services and Adaptive Authentication instances are updated directly by Cloud Software Group.

Administrators can ascertain potential exposure by checking their configurations for either add authentication samlAction, which denotes a SAML service provider, or add authentication samlIdPProfile, indicating a SAML identity provider. The presence of either of these configurations on an affected build signifies potential vulnerability, though it does not confirm a compromise.

Customers are advised to upgrade to version 14.1-73.41 or later for the 14.1 branch, or 13.1-64.28 or later for the 13.1 branch. FIPS customers should install 14.1-73.41 FIPS or newer, while 13.1 FIPS and NDcPP deployments require 13.1-37.282 or later within their respective branches.

Even organizations that have recently applied previous NetScaler security updates must update again if their systems meet the conditions for this new vulnerability. While Citrix is providing Global Deny Lists to block known malicious IP addresses, prompt patching remains the most critical mitigation. Citrix’s advisory credits Bishop Fox and watchTowr for their assistance in protecting customers.

What You Should Do

  • Immediately identify all NetScaler ADC and Gateway appliances configured as SAML service or identity providers.
  • Verify the version of all identified appliances against the list of affected versions in the Citrix’s security bulletin.
  • Apply the recommended emergency security updates (14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, 13.1-37.282 or later) as soon as possible.
  • Even if your systems were recently patched for other vulnerabilities, re-patching for this specific CVE is crucial if your configuration is affected.
  • Monitor your NetScaler appliances for unusual activity, repeated reboots, or signs of compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Top 10 Machine Identity Management Solutions for 2026

Next Post

Top Fine-Grained Authorization Tools for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Citrix, FortiMail, and Apple Zero-Days Expose Users
October 5, 2026
South Korean President Orders Full Security Checks After Financial Sector Hacks
October 4, 2026
ShinyHunters Member Arrested, Cooperating with FBI in Jordan
October 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us