Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already Patched
Security / news
Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already Patched
CVE-2026-88779 hits SAML-configured NetScaler boxes that had just taken the Sept. 27 fixes, and attackers were already trying to drop a payload through it.

A remote attacker who can reach a NetScaler ADC or Gateway configured for SAML can crash the appliance, including builds that were patched a week earlier for two other Citrix zero-days. Citrix disclosed the flaw, CVE-2026-88779, on Oct. 4, and CISA added it to its Known Exploited Vulnerabilities catalog the same day.
BleepingComputer reports a federal mitigation deadline of Oct. 7. The fixed builds are 14.1-73.41 and 13.1-64.28, and customers who already moved to 14.1-73.37 or 13.1-64.23 for the September batch have to upgrade a second time if the SAML precondition applies to them.
What CVE-2026-88779 is rated, and what was seen
Citrix rates the flaw 8.7 and describes it as a denial-of-service memory overflow in SAML processing. It says it "has not identified an impact on the integrity of customer data." An appliance is exposed if the configuration contains add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider).
The score may understate what attackers tried. An administrator posting on Reddit saw crafted usernames containing shell commands that would fetch a payload from 213.209.159[.]55, save it as /v and run it. The logs showed attempts and matching crashes but not confirmed execution. Researcher Kevin Beaumont reported that patched NetScaler 13.1 and 14.1 honeypots crashed, and that one was running a downloaded malware binary. BleepingComputer says researchers are still checking whether remote code execution is possible. watchTowr Labs said it reproduced the bug and has not published details.
| CVE | Flaw | CVSS v4.0 | Precondition |
|---|---|---|---|
| CVE-2026-88771 | Input validation, unauthenticated RCE | 9.5 | Any default deployment |
| CVE-2026-88772 | Memory overflow, RCE or denial of service | 9.5 | DTLS enabled (default on VPN vServers) |
| CVE-2026-88779 | SAML memory overflow | 8.7 | SAML SP or IdP configured |
The first two rows come from Citrix bulletin CTX697096, published Sept. 27. The third comes from Rapid7's update of its own advisory.
How the first two zero-days unfolded
The earlier flaws had a longer run before anyone was told. Rapid7's managed detection team logged the first attempt against CVE-2026-88771 at 14:28:43 UTC on Sept. 20, seven days before Citrix published anything.
- Sept. 20: two exploitation attempts seen by Rapid7 MDR.
- Sept. 24: GreyNoise recorded a zero-day attempt against a Gateway, and Rapid7 found a webshell at a second victim.
- Sept. 27: Citrix disclosed eight CVEs (CVE-2026-88771 to CVE-2026-88778); CISA listed 88771 and 88772.
- Oct. 1: Help Net Security reported mass exploitation after watchTowr Labs published a root-cause analysis and proof of concept for CVE-2026-88771.
- Oct. 4: CVE-2026-88779 disclosed and added to KEV.
What attackers took is specific. In one Rapid7 case a command injection ran tar over the device's /flash/nsconfig directory and left the archive at /var/netscaler/gui/vpn/c, which anyone could download from /vpn/c without logging in. That archive holds encrypted admin passwords, LDAP, RADIUS and TACACS bind passwords, SSL private keys and SSH host keys.
Exposure and what to do first
Censys counted about 42,000 internet-facing NetScaler hosts, 13,549 of them (32%) in the United States and 5,678 (13%) in Germany, according to Help Net Security. Censys cannot say which are vulnerable. Beaumont put the patched share below 10% and said he was tracking more than 100 victim organisations, each with a webshell only its operator can find.
CISA's alert tells administrators to check for compromise before patching, because updates "may result in loss of forensic visibility." The order is therefore: preserve evidence, follow Citrix's compromise guide (CTX694799), install 14.1-73.41 or 13.1-64.28, then rotate every credential stored on the box. Rapid7 lists the webshell path /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver as an indicator.
No public proof of concept exists yet for CVE-2026-88772, and none has been published for CVE-2026-88779. watchTowr published one for 88771 within days of disclosure, This site has also reported zero-days in Fortinet's FortiMail (CVE-2026-104286) and F5's BIG-IP APM (CVE-2026-94127) since Oct. 8. The next date to watch is whenever it releases the SAML details.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.