Yaamlabs

Vulnerabilities

Patched NetScalers reboot as a new SAML flaw is attacked

Crafted SAML requests crash the nsaaad service on NetScalers already on the September fix. No CVE or fixed build yet: how to check exposure and what to watch.

NetScaler ADC and NetScaler Gateway appliances that were already upgraded for last week's zero-days are crashing and rebooting under a new attack. Since the evening of October 2, crafted SAML requests have been crashing nsaaad, the appliance's authentication daemon, including appliances on 14.1-73.37 and on patched 13.1 builds, the releases that fixed CVE-2026-88771 and CVE-2026-88772. Citrix confirmed on October 2 that it is investigating "a newly identified issue" with SAML authentication on customer-managed appliances, and said a security bulletin and a fixed build will be released together.

As of October 4 there is no bulletin, no CVE ID, no list of affected builds and no fixed build. Citrix says the issue applies to appliances that use SAML authentication with Gateway or AAA (authentication, authorisation and auditing) virtual servers. If you have no SAML actions or SAML identity provider profiles configured, Citrix's guidance indicates you are not affected. If you do, the September upgrade does not protect you from this.

How it works

SAML (Security Assertion Markup Language) is the single sign-on protocol that lets a NetScaler hand logins to an identity provider such as Microsoft Entra ID, or act as the identity provider itself. When the NetScaler is the service provider, the user's browser posts a signed assertion back to the Gateway, by default at /cgi/samlauth, and nsaaad parses it. That parsing happens before the user is authenticated, so anyone who can reach the Gateway's login page can send it data.

Malformed SAML data makes nsaaad crash. NetScaler restarts a crashed daemon, but its watchdog process, pitboss, counts the failures. Once nsaaad hits its restart limit, pitboss declares a system failure and reboots the whole appliance. Administrators on Reddit described scans followed by repeated nsaaad crashes and then forced reboot cycles on external appliances running 14.1-73.37. In a high availability (HA) pair, the crashes can also trigger a failover to the secondary node.

Citrix has not published the root cause, and it calls the issue configuration dependent and separate from bulletin CTX697096. The Australian Cyber Security Centre (ACSC) also describes it as separate from the two September CVEs.

What attackers are doing

Security researcher Kevin Beaumont reported on October 2 that his patched NetScaler honeypots, on both 13.1 and 14.1, were crashing, and that one of them was running a downloaded malware binary. He named the activity "PitScaler 2" and suggested the September fix may have been bypassed. heise reported that the watchTowr Labs team has reproduced the vulnerability. watchTowr's public FAQ on the zero-days has no entry on it yet.

The open question is whether this is a bypass of the September fix or a separate flaw in the SAML code. Citrix describes the issue as independent of CTX697096, and the reboot reports alone do not prove a bypass. Beaumont's honeypots show code execution on patched builds either way. Until Citrix publishes the bulletin, treat any appliance in scope as exposed to a pre-authentication flaw with reported code execution on current builds.

No victim count, attribution or list of attacking addresses has been confirmed by Citrix or a government agency. ACSC asks affected organisations to contact Citrix Support and report to it.

Citrix Support has been giving affected customers a responder policy (a NetScaler rule that inspects requests and drops or answers them before they reach the authentication code) aimed at the SAML endpoints. It has not been published. Beaumont reported that the policy did not stop the crashes on his systems, and Reddit commenters who applied it said it did not change anything.

What to do

There is no fix to install yet, so the work is reducing exposure, watching for the crash pattern and being ready to patch the moment Citrix publishes.

  1. Stay on the September builds. Do not roll back from 14.1-73.37 or 13.1-64.23 to stop the reboots. Older builds are open to CVE-2026-88771 and CVE-2026-88772, which are exploited and need no SAML configuration.
  2. Find out whether you use SAML. On each appliance run show authentication samlAction and show authentication samlIdPProfile, or from the shell grep -iE "add authentication saml(Action|IdPProfile)" /nsconfig/ns.conf. Any match on an appliance that serves an internet-facing Gateway or AAA virtual server puts it in scope.
  3. Watch for the crash pattern. Look in /var/log/ns.log and /var/log/messages for nsaaad exiting on a signal, nsaaad reaching its maximum number of restarts, and pitboss declaring a system failure. New nsaaad core files in /var/core are another sign. On HA pairs, run show ha node and check for unexpected changes of primary node; a failover moves the same traffic to the other node, so plan for both nodes being hit.
  4. Preserve evidence before a reboot clears it. Copy the core files, ns.log, /var/log/messages and a support bundle (show techsupport) off the appliance before rebooting or upgrading. Beaumont's honeypots fetched and ran a payload before crashing, so after a crash, look for new or unknown files and running processes on the appliance.
  5. Ask Citrix Support for the responder policy if you are affected, apply it, and keep watching the logs, because researchers report it does not stop every crash.
  6. Consider turning SAML off temporarily where you can. Security firms have suggested disabling SAML where it is not essential, or limiting external access to the login page, until the fix ships. Citrix has not recommended this, and it means users lose single sign-on, so weigh it against the risk of running a pre-authentication flaw with reported code execution.
  7. Be ready for the bulletin. Subscribe to Citrix security bulletins and plan an upgrade window for every node of each HA pair or cluster. When the fixed build is out, upgrade, then run the compromise checks from our September post again.

Reboots are a security signal

Many teams treat an appliance that reboots by itself as an availability ticket: the network team restarts it, checks that the VPN is back and closes the case. On a NetScaler a week after two exploited zero-days, an unexplained nsaaad crash should go to the security team too. Send ns.log and the system log to your security monitoring, alert on daemon crashes, pitboss restarts and HA state changes, and keep a short runbook for collecting core files before anyone power-cycles the box.

If you want an outside check of which edge appliances you expose and on what builds, our attack surface management work starts there, and our security operations team can set up the alerting for crash and failover events. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: heise, Born's IT and Windows blog, Citrix guidance for NetScaler SAML authentication deployments, Cyber Security News, GBHackers, Mallory, PitScaler tracker, ACSC alert, watchTowr FAQ, NetScaler docs: NetScaler as a SAML SP.

Back to the blog, or read this post on the full site.