NetScaler CVE-2026-88779: how to detect exploitation attempts
CVE-2026-88779 is an out-of-bounds write (CWE-119) in NetScaler SAML authentication that causes denial of service. Detection focuses on repeated appliance reboots, spikes in SAML endpoint errors and drops in successful authentication. Citrix reports no identified impact on customer data integrity.
- CWE-119 flaw in NetScaler SAML authentication causes denial of service
- Main attack sign is repeated appliance reboots without manual intervention
- Config markers samlAction and samlIdPProfile show if an appliance is in scope
- Fix is patching to fixed builds; Global Deny List and IP blocks help meanwhile
Read next
Security