Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited List
Security / news
Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited List
Builds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.

An attacker who can reach a NetScaler ADC or Gateway appliance configured as a SAML service provider or identity provider can trigger a memory-overflow flaw, CVE-2026-88779, without logging in. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on October 4 and gave federal agencies until October 7 to act.
The fix is a second round of updates. The builds that Citrix shipped on September 27 for two other exploited flaws (14.1-73.37 and 13.1-64.23) are listed as affected, according to Qualys ThreatPROTECT.
What the October 4 entry covers
CISA's catalog describes CVE-2026-88779 as a denial-of-service flaw in NetScaler ADC and NetScaler Gateway. Qualys lists the fixed builds as 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 FIPS/NDcPP.
Citrix's own page for this CVE, linked from the KEV entry, returned an access error when fetched for this report. The version figures therefore rest on Qualys alone, and operators should confirm them against Citrix before changing production.
One field in the KEV record matters more than the label. The entry carries forensicTriage: Yes, which means agencies must check the appliance for compromise as well as patch it, a duty CISA's BOD 26-04 attaches to its fastest three-day tier. A flaw labelled denial of service is being handled like a takeover candidate.
| CVE | Precondition | CVSS v4 | KEV due date |
|---|---|---|---|
| CVE-2026-88771 | Default deployment | 9.5 | September 30 |
| CVE-2026-88772 | DTLS enabled (default on VPN virtual servers) | 9.5 | September 30 |
| CVE-2026-88779 | SAML service provider or identity provider | Not in sources read | October 7 |
The September bulletin and its timeline
Citrix bulletin CTX697096, published September 27, covers eight CVEs numbered CVE-2026-88771 through CVE-2026-88778. It marks two as exploited in the wild: CVE-2026-88771, an input-validation flaw that lets an unauthenticated attacker run commands on default deployments, and CVE-2026-88772, a DTLS buffer overflow.
- CVE-2026-887719.5 score
- CVE-2026-887729.5 score
- CVE-2026-887739.3 score
- CVE-2026-887758.8 score
- CVE-2026-887747 score
Source: Citrix bulletin CTX697096, accessed 2026-10-06
- Early September: exploitation of CVE-2026-88772 begins, according to Mandiant and Google Threat Intelligence Group.
- September 27: Citrix publishes CTX697096; CISA adds CVE-2026-88771 and CVE-2026-88772 with a September 30 due date.
- October 4: CISA adds CVE-2026-88779, due October 7.
- October 5: Qualys publishes the fixed-build list.
Mandiant and Google Threat Intelligence Group found organisations across government, education, technology, financial services and legal services in North America and Europe likely affected, Help Net Security reported. Mandiant CTO Charles Carmakal attributed the targeted intrusions to "advanced and suspected state-sponsored threat actors". Its researchers wrote that exploitation "bypasses authentication and triggers unhandled termination of the NetScaler Packet Processing Engine to establish initial root-level access."

What to do now
Check whether the appliance is a SAML service provider or identity provider; if it is, move to 14.1-73.41, 13.1-64.28 or the matching FIPS build. A box already moved to 73.37 or 64.23 on September 27 is not finished. Citrix's guidance, as quoted in the KEV notes, says running the supplied indicators of compromise in the NetScaler console may help identify exploitation.
Buffer-handling bugs of this class are the subject of our report on GrapheneOS and Pixel 11 memory tagging, and CISA's other October addition with a three-day clock is covered in the Zammad session-fixation entry.
The next fixed date is October 7, when federal agencies must have patched and triaged. The KEV catalog does not say whether CVE-2026-88779 has been tied to the same intrusion set as the September zero-days.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04FortiMail CVE-2026-104286: Exploited 9.8 Flaw Lets Unauthenticated Requests Write FilesFortinet's advisory lists a workaround and fixed builds for three release branches; the 7.2 branch gets none.