NetScaler administrators are currently navigating another difficult weekend following emergency efforts to secure their infrastructure against critical zero-day threats a week ago, and now many organizations are reporting that their appliances have entered forced, recurring reboot cycles.

The initial patches were released to address CVE-2026-88771 and CVE-2026-88772, which were under active exploitation and allowed for unauthenticated remote code execution. Security teams across the industry prioritized the installation of build 14.1-73.37 and other relevant versions to mitigate these risks. However, post-deployment reports indicate that the nsaad authentication daemon is crashing when encountering specific, crafted SAML authentication traffic.

 In high-availability environments and internet-facing gateways, this failure triggers the platform’s internal watchdog mechanism, which force-restarts the appliance, leading to a significant denial-of-service condition.

Citrix has acknowledged the issue and is currently tracking the instability through their engineering and support teams. The vendor says this is a configuration-dependent issue rather than a failure of the security patches themselves. 

“The issue is associated with NetScaler deployments that use SAML authentication in conjunction with Gateway or AAA functionality. Customers who have deployed NetScaler as a Gateway or AAA virtual server should review their NetScaler configurations to determine whether SAML authentication actions are configured,” the Citrix advisory says.

Specifically, the problem appears to affect NetScaler ADC and Gateway deployments where SAML authentication is active, and the presence of commands such as add authentication samlAction or add authentication samlIdPProfile as common denominators. Citrix maintains that this reboot behavior is distinct from the vulnerabilities addressed in last week’s bulletin and is not an indication that the initial fixes have been bypassed.

Researchers at watchTowr, who were among the first to post publicly about the initial Citrix flaws last weekend, have taken a look at the new issue and have been able to reproduce it, as well.

"Unfortunately? Fortunately? the watchTowr Labs team has now successfully reproduced this vulnerability. watchTowr Platform clients now have mitigation rulesets available to them via our Active Defense capability," the company said.

Organizations should maintain the current security patches in place, as they remain essential for defending against the initial remote code execution flaws. While awaiting a new security bulletin and a new, corrected build from the vendor, administrators are encouraged to review their Gateway and AAA configurations for the specific SAML-related command configurations noted by Citrix. 

Citrix is telling affected customers to contact support if they’re seeing the problems described in the advisory.