Skip to content
Security & Trust

Exploited NetScaler flaw can lock out a company that uses SAML sign-in

CVE-2026-88779 lets unauthenticated attackers crash SAML sign-in, putting VPN and single sign-on access at risk

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Exploited NetScaler flaw can lock out a company that uses SAML sign-in
In brief
  • Orca Security reports that CVE-2026-88779 lets unauthenticated attackers crash the SAML login service on Citrix NetScaler ADC and Gateway, and that Citrix has confirmed targeted exploitation in the wild.
  • One appliance can sit in front of VPN and single sign-on for a whole organization, so a crash can potentially lock out everyone who signs in through it.
  • Check whether SAML is configured, upgrade to the fixed builds, and test how staff would sign in if single sign-on went down.

An attacker does not need to get inside a company to halt it. Sometimes it is enough to switch off the login.

That is the risk in CVE-2026-88779, a flaw in Citrix NetScaler ADC and NetScaler Gateway. Orca Security published its analysis on October 5. The lesson here is that single sign-on turns one appliance into the front door for everyone. When that door jams, the whole organization can end up waiting outside.

What is confirmed

Orca reports that specially built network requests can crash the SAML login service on affected appliances. The sender does not need to sign in first. Orca says repeated requests can keep the service down.

Orca also reports that Citrix has confirmed targeted exploitation in the wild. The security firm watchTowr Labs saw activity on its NetScaler honeypot and then reproduced the flaw on its own.

On October 4, CISA placed the flaw on its list of vulnerabilities known to be under attack.

8.7
CVSS v4.0 severity score
Source: Orca Security (October 5, 2026)
October 7, 2026
Federal remediation deadline set by CISA
Source: Orca Security, citing CISA KEV (October 5, 2026)

That deadline binds federal agencies only. Other organizations set their own pace.

How the flaw works

SAML is the standard that lets one sign-in unlock many applications. A NetScaler can play two roles. As a service provider, it asks another system to vouch for a user. As an identity provider, it does the vouching.

Both roles run through a component called nsaaad. It handles SAML login requests. Orca traces the flaw to a memory overflow (CWE-119) inside nsaaad. The program receives more data than it made room for, and the service crashes.

No sign-in is required. Anyone who can reach the appliance can send the requests.

Orca says the risk applies when SAML is switched on with one of two settings. These are add authentication samlAction for the service provider role, and add authentication samlIdPProfile for the identity provider role.

The human cost is easy to picture. Employees may be unable to connect to the VPN or open the apps behind single sign-on. Orca says the crash can potentially lock out all users. The outage can reach everyone who signs in through that appliance, not one team.

Who is affected

Orca frames the fix by build number. Standard ADC and Gateway on the 14.1 branch need build 14.1-73.41. On the 13.1 branch they need 13.1-64.28. Older builds on either branch are exposed.

The 14.1 FIPS edition of ADC uses the same fix, 14.1-73.41. The 13.1 FIPS and NDcPP editions of ADC need build 13.1-37.282.

Citrix-managed cloud services are not affected. Secure Private Access Hybrid setups that rely on a vulnerable NetScaler are in scope.

6
Exploited NetScaler vulnerabilities added to CISA KEV in 2026
Source: Orca Security (October 5, 2026)

What is not yet known

Orca says some researchers see signs that the overflow could also allow remote code execution. That would let an attacker run commands on the appliance. Citrix has not confirmed this.

Until it does, the documented impact is a service outage.

The report does not say how many appliances have been hit. Orca also sells tools that map exposure, so treat its product claims separately. The technical findings are backed by watchTowr's reproduction and by Citrix's confirmation.

Questions to put to your team

First, do we run NetScaler ADC or Gateway? Which versions? Second, is SAML set up on any of them, using either of the two settings above?

Third, have we moved to the fixed builds listed above? Fourth, are we watching for unexplained nsaaad crashes or appliance reboots? Orca names both as signs of compromise.

Fifth, has someone blocked the attacker address Orca reports, 213.209.159[.]55? Sixth, if single sign-on went down for a day, how would staff reach critical systems? Test that answer before an outage forces it.

A login service is only as available as the one box in front of it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Orca Security.

Share this insight