NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload Download
Security / news
NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload Download
Citrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.

An unauthenticated attacker who can reach the SAML login path on a NetScaler ADC or Gateway (configured as a SAML service provider or identity provider) can overflow memory and take the appliance down. CISA added the flaw, CVE-2026-88779, to its Known Exploited Vulnerabilities catalog on October 4, 2026.

Citrix rates the flaw 8.7 on CVSS v4 and classifies it as a memory buffer error (CWE-119) with denial of service as the impact. Its bulletin, CTX697174, credits Bishop Fox and watchTowr with the report. The Hacker News quotes the advisory as confirming attacks on unmitigated deployments, with no customer data integrity impact identified.
Which NetScalers are exposed
The precondition is configuration, not version alone. An appliance is reachable only if its config contains add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider). Citrix-managed cloud instances are already patched, according to the bulletin.
| Branch | Vulnerable before | Fixed build |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.41 | 14.1-73.41 |
| NetScaler ADC and Gateway 13.1 | 13.1-64.28 | 13.1-64.28 |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1-37.282 | 13.1-37.282 |
The 14.1-FIPS branch is also affected and takes the 14.1-73.41 FIPS build, per GBHackers.
The score may understate what attackers are doing
BleepingComputer reports that one administrator found crafted authentication usernames containing shell commands that fetch a payload from 213.209.159[.]55. It also reports that Kevin Beaumont, a security researcher, found a downloaded binary running on a patched honeypot and described it as a new vulnerability beyond the denial of service.
WatchTowr Labs reproduced the bug and withheld technical details, BleepingComputer said. Citrix's bulletin does not mention code execution. Until the vendor or a researcher publishes the mechanism, the denial-of-service rating is the only characterisation with a named source behind it, and the shell-command reports are a single outlet's account of other people's observations.
Timeline from October 3 to October 7
- October 3: Citrix publishes CTX697174, dated October 3 Pacific time in the bulletin listing.
- October 4: BleepingComputer reports builds 14.1-73.41 and 13.1-64.28 became available early Sunday; CISA adds CVE-2026-88779 to the KEV catalog the same day.
- October 7: deadline for federal civilian agencies to mitigate, under CISA's binding directive.
The sources disagree by a day on when the fixes appeared, and the bulletin text does not say when exploitation was first seen.
This is the second NetScaler update in a week
Citrix said the new builds must be applied even on appliances updated for CVE-2026-88771 through CVE-2026-88778, the batch we covered on web shells that survive the patch. The earlier fix does not address this flaw. A pattern of edge appliance exploitation is also visible in FortiMail's unpatched CVE-2026-104286.
Operators with SAML configured should move to 14.1-73.41 or 13.1-64.28 (13.1-37.282 on FIPS and NDcPP) before October 7, and check appliance crash logs and SAML authentication failures from the past week. Anyone who finds a username containing shell syntax should treat the box as compromised, not merely crashed.
Sources
More in Security
- 01Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 02Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 03Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.
- 04FortiMail CVE-2026-104286 Is Exploited With No Fixed Release, and the Workaround Is Turning Off a FeatureAn unauthenticated path-traversal bug scoring 9.8 lets an attacker write files to FortiMail 7.2 through 8.0. CISA's deadline is October 4; Fortinet had no patch when the advisory went out.