Pagine

▼

CITRIX #NetScaler CVE-2026-88779

Citrix released new CVE bullettin.

Affected Netscaler versions are:

  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix article explain how to determine if an appliance meets the CVE preconditions.

Meanwhile I share steps to be done on Netscaler:

a) Connect though SSH to search if saml is configured using these commands:

  • show ns runningConfig | grep -i saml
  • show authentication samlAction
  • show authentication samlIdPProfile
  • b) Though GUI:

    1. Log in on Netscaler
    2. Configuration search for --> saml
    3. Configuration --> Security ---> AAA-Application Traffic --> Policies --> Authentication