TL;DR
Citrix admins report NetScaler appliances rebooting repeatedly even after updating to build 14.1-73.37. Citrix now says it is tracking a new issue tied to NetScaler SAML authentication. A fix and security bulletin are planned, but no patch exists yet.
- Product: Citrix NetScaler ADC
- Vulnerabilities: 2 flaws (CVE-2026-88771, CVE-2026-88772)
- Highest severity: 9.5 (Critical · CVSSv4)
- Worst impact: A remote code execution exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
- Status: 2 exploited; patches available
- Exploit Intel (PatchThis): 2 of 2 confirmed
- Action: Update to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS and NDcPP now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-88771 | 9.5 | A remote code execution exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS (+1) | Exploited |
| CVE-2026-88772 | 9.5 | Memory overflow leading to Remote Code Execution or Denial of Service | 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS (+1) | Exploited |
Too many Citrix alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysWhy It Matters
The reports follow Citrix’s September 27 disclosure of CVE-2026-88771 and CVE-2026-88772. Attackers exploited both critical flaws as zero-days. Palo Alto Networks Unit 42 counted 50,277 exposed instances that could be vulnerable, based on its Cortex Xpanse telemetry.
Now, patched devices are misbehaving. In a Reddit thread on NetScaler activity after patching, one admin said several customers saw internet-facing appliances reboot over and over. Others saw the same on freshly rebuilt appliances with Enhanced ISN Generation enabled.
How the Attack Works
Citrix has not described the mechanism. So far, it remains unclear whether the reboots reflect a new flaw, leftover compromise, scanning, or a firmware bug. However, Citrix ties the new issue to SAML. It explains that “this issue is configuration dependent.” The company also states that it “is independent of the vulnerabilities disclosed in CTX697096.”
Affected Versions
Citrix lists no affected builds yet. Instead, it flags any Gateway or AAA deployment that uses NetScaler SAML authentication. Specifically, Citrix says “the NetScaler is affected when at least one of the following SAML commands is present”:
- add authentication samlAction
- add authentication samlIdPProfile
Patch and Mitigation Steps
Citrix’s guidance for NetScaler SAML authentication deployments lists three actions:
- Check Gateway and AAA configurations for SAML authentication actions.
- Contact Citrix support if you already see impact.
- Upgrade as soon as the new security bulletin ships.
Meanwhile, keep the 14.1-73.37 or 13.1-64.23 fixes in place. Unit 42 warns that patching “will not remove access for attackers that have already established persistence.” Therefore, teams should also hunt for web shells and backdoors.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!