New Citrix NetScaler SAML Flaw Triggers Crashes and Suspected Exploitation Attempts

New Citrix NetScaler SAML Flaw Triggers Crashes and Suspected Exploitation Attempts

By Tamilselvan
Publication Date: 2026-10-03 05:36:00

Citrix NetScaler administrators are reporting repeated appliance crashes and forced reboots after applying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML authentication deployments.

The incidents have been reported on internet-facing NetScaler ADC and Gateway appliances running patched releases, including version 14.1-73.37.

Multiple administrators said malicious or malformed SAML-related requests appeared to crash the nsaaad authentication service, triggering failovers or full appliance reboots.

New Citrix NetScaler SAML Flaw

Reddit said the activity has not been independently confirmed as successful exploitation of the new SAML issue, but accounts of payload-bearing requests, attempted script downloads, and repeated service failures have raised concerns that attackers are probing exposed systems.

NetScaler engineering and support teams said they are tracking an issue…