Citrix NetScaler appliances reboot repeatedly after emergency zero-day patch
Admins report NetScaler ADC and Gateway devices on build 14.1-73.37 rebooting after SAML traffic crashes the nsaaad service. Citrix is preparing a new bulletin and fixed build.
At a glance
- Admins report repeated reboots on NetScaler build 14.1-73.37, the emergency fix for exploited CVE-2026-88771 and CVE-2026-88772.
- Crafted or malformed SAML authentication traffic reportedly crashes the nsaaad service, triggering failovers or watchdog restarts.
- Citrix says it is tracking a newly seen SAML issue and plans a fresh security bulletin and fixed build.
- There is no confirmation that the September patch has been bypassed; admins are urged to preserve evidence before restarting.
Organizations that rushed to install Citrix's emergency update for two actively exploited NetScaler zero-days are now reporting a new problem: appliances that keep rebooting. According to reports published on October 3 by Cyber Security News and GBHackers, administrators running NetScaler ADC and NetScaler Gateway build 14.1-73.37 have seen repeated restarts that appear to be linked to crafted SAML authentication traffic. Citrix has acknowledged the issue and is preparing another fix, the reports said.
What happened
In late September, Citrix released patches for eight NetScaler vulnerabilities, two of which, CVE-2026-88771 and CVE-2026-88772, were already being exploited in the wild. SecurityWeek reported at the time that the Dutch National Cyber Security Centre had privately pre-notified organizations, prompting some administrators to shut down their appliances before patches were available, and that CISA added both flaws to its Known Exploited Vulnerabilities catalog.
After installing the emergency build, several customers began reporting unexpected reboots. According to Cyber Security News, the reports came from administrators managing internet-facing appliances on Reddit and from multiple customers who opened severity-one support cases with Citrix; some noted that vulnerability scan traffic preceded the crashes. These community reports have not been independently verified.
Technical details
Per both publications, administrators said crafted, malicious or malformed SAML-related requests appeared to crash nsaaad, the appliance's authentication service. Repeated daemon failures can trigger high-availability failovers or cause the appliance watchdog, known as pitboss, to restart the entire device once a crash threshold is reached.
CVE-2026-88771, rated 9.5 under CVSS v4.0, allows unauthenticated remote command execution and affects default configurations, according to SecurityWeek. CVE-2026-88772, also rated 9.5, is a memory overflow that can lead to code execution or denial of service on appliances with DTLS enabled, which is the default on VPN virtual servers.
Cyber Security News stressed that the reboot reports do not prove attackers have bypassed the September patch. Citrix said its engineering and support teams are tracking a newly seen SAML issue and plan to release a fresh security bulletin and a fixed build, the outlet reported. No CVE has been publicly assigned to the SAML issue so far.
Who is affected
The reports center on NetScaler ADC and Gateway appliances running build 14.1-73.37, particularly externally exposed systems with SAML authentication configured. GBHackers also listed releases from 13.1-64.23 onward among the affected builds, along with FIPS and NDcPP variants mentioned by Cyber Security News.
What to do
The reports do not suggest rolling back the zero-day fix, which addresses flaws under active attack. Instead, they recommend that administrators:
- Review SAML authentication action configurations on internet-facing appliances.
- Preserve core files, logs, support bundles and firewall telemetry before restarting a device.
- Monitor for recurring
nsaaadcrash messages and correlate reboot times with SAML requests. - Confirm the installed build on both active and standby nodes.
- Keep support cases open and watch for Citrix's upcoming bulletin and fixed build.
Cyber Security News also reminded readers that patching does not remove web shells or other access an attacker may have established before the update, so compromise checks remain necessary.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



