Skip to content
VulniPulse
Advisory severityUnratedNetScaler (Citrix)

Advisory Security Update: Guidance for NetScaler SAML Authentication Deployments

This security NetScaler (Citrix) advisory covers CTX697096.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CTX697096 Source published

VulniPulse record published

Related products & platforms
NetScaler (Citrix)NetScaler Gateway
Open source advisory

Android app · Google Play

Monitor NetScaler (Citrix) CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, how to determine whether the relevant configuration is present, and what mitigation options are available while planning an upgrade to a fixed build.

A new security bulletin and a new blog has been published. The guidance below is intended to help customers take immediate action to reduce exposure.

As with any security-related issue, customers should prioritize applying the updated NetScaler builds referenced in the applicable security bulletin. What is being observed The issue is associated with NetScaler deployments that use SAML authentication in conjunction with Gateway or AAA functionality.

Customers who have deployed NetScaler as a Gateway or AAA virtual server should review their NetScaler configurations to determine whether SAML authentication actions are configured. Based on the information currently available to us, this issue is configuration dependent.

Customers should search for the following configuration patterns in their NetScaler configurations to determine applicability.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · low-confidence parse· fetched 3 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · low-confidence parse· fetched 3 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • We recommend that customers bookmark and monitor this article for the latest updates.
  • Subscribe to Security Bulletins Citrix strongly recommends that all customers subscribe to receive alerts when a Citrix security bulletin is created or modified at https://support.citrix.com/wolken-support/view/aboutsupport/my-support-alerts Last Updated on: October 3, 2026 (Pacific Daylight Time)

Official advisory · low-confidence parse· fetched 3 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.