September’s emergency NetScaler fixes did not eliminate repeatable unauthenticated SAML outages.
Citrix reports targeted attacks, and CISA has added the flaw to its exploited-vulnerability catalog.
Customer-managed NetScaler ADC and NetScaler Gateway appliances providing application delivery, AAA and remote-access VPN services.
Unauthenticated persistent denial of service against SAML authentication gateways
An unauthenticated client can still repeatedly crash SAML-enabled NetScaler gateways after the emergency fixes, and Citrix reports attacks against unmitigated deployments.
Detail and 2 sources
An unauthenticated client can reach the memory-overflow path on a Gateway or AAA virtual server where NetScaler acts as a SAML service provider or identity provider, then repeat the trigger to keep the service unavailable.
Citrix has not identified an integrity impact, and reports calling the flaw remote code execution remain unconfirmed.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
The EOL finding concerns patch availability; public vendor material does not confirm whether CVE-2026-88779 affects the EOL branches.