NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is Today
Security / news
NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is Today
Citrix rates the flaw 8.7 and calls it a denial of service, but a researcher's honeypot ran a downloaded binary, and appliances patched for last week's bugs need a second upgrade.

An unauthenticated attacker can crash a Citrix NetScaler ADC or Gateway appliance repeatedly through CVE-2026-88779 (CVSS 4.0 score of 8.7), provided the appliance is configured as a SAML service provider or identity provider. Citrix says the flaw is being exploited in targeted attacks on unmitigated deployments. CISA added it to the Known Exploited Vulnerabilities catalog on October 4 and set a deadline of today, October 7, for federal civilian agencies.
Fixed builds are NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28. Customers who upgraded last week to fix CVE-2026-88771 through CVE-2026-88778 and who use SAML must upgrade again, according to BleepingComputer's report on Citrix advisory CTX697174.
Which NetScaler appliances are exposed to CVE-2026-88779
Exposure depends on configuration, not on version alone. An appliance is potentially affected if its configuration contains either add authentication samlAction (SAML service provider) or add authentication samlIdPProfile (SAML identity provider). Administrators can search the running configuration for both strings.

The fix table below comes from the same advisory as relayed by The Hacker News and BleepingComputer.
| Branch | First fixed build |
|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.41 |
| NetScaler ADC and Gateway 13.1 | 13.1-64.28 |
| 14.1 FIPS | 14.1-73.41 FIPS |
| 13.1 FIPS and NDcPP | 13.1-37.282 |
Timeline from Friday, October 2 to Sunday, October 4
The sequence matters because the fix arrived after the attacks did.
- Friday, October 2: administrators report patched appliances rebooting without warning. Citrix publishes a notice saying it is tracking a "newly observed issue" in SAML authentication, separate from the earlier flaws.
- Sunday, October 4: Citrix ships the fixed builds, and CISA lists the CVE with a three-day due date.
- Monday, October 5: The Hacker News reports Citrix's confirmation of "targeted attacks on unmitigated NetScaler deployments" and credits Bishop Fox and watchTowr in Citrix's advisory.
watchTowr Labs says it reproduced the flaw within hours of seeing NetScaler honeypot activity. It has not published technical details.
What the evidence says about denial of service versus code execution
Citrix describes a memory overflow that causes denial of service. It says it has "not identified an impact on the integrity of customer data."
The score overstates nothing on availability, since repeated triggering can leave the service unavailable. It may understate the risk if the overflow can be pushed further. BleepingComputer reports three observations that point past a crash:
- Administrators saw the
nsaaadprocess crash repeatedly on 14.1-73.37 until the Pitboss supervisor hit its restart limit and rebooted the appliance, including on freshly rebuilt images. - One administrator found crafted authentication usernames containing shell commands meant to download a payload from 213.209.159[.]55, save it as
/vand execute it. The logs show the attempt, not that the commands ran. - Security researcher Kevin Beaumont reported that patched 13.1 and 14.1 honeypots crashed after requests from several source IPs, and later found one honeypot running a downloaded malware binary, which he said showed the activity went beyond denial of service.
Beaumont compared the situation to CVE-2025-6543, first described as a denial of service and later used for remote code execution. No researcher has published a working code-execution chain for CVE-2026-88779.
How CVE-2026-88779 relates to CVE-2026-88771 and CVE-2026-88772
Citrix confirmed CVE-2026-88771 and CVE-2026-88772 as exploited zero-days in late September, both with CVSS 4.0 scores of 9.5. Palo Alto Networks' Unit 42 counted 50,277 potentially vulnerable internet-exposed instances on September 27 and recorded a web shell dropped at a US target on September 21, before the bulletin. Its own guidance says patching "will not remove access for attackers that have already established persistence."
That caveat applies here too. An appliance patched for the first two flaws and then rebooted by this one may already carry a web shell from the earlier campaign. Hunting for that, as CISA's own catalog entry implies by marking forensic triage required under Binding Operational Directive 26-04, is separate from installing 14.1-73.41. The directive's schedule is analysed in our report on CISA's three-day deadlines.
FortiMail's CVE-2026-104286 was exploited at disclosure with no fixed build at all, which makes Citrix's two-day gap between notice and patch look short.
What to do before the end of October 7
Administrators of SAML-configured NetScalers should install 14.1-73.41 or 13.1-64.28, then check for the /v download and for unexpected reboots in the logs. Ransomware use is listed as unknown in the CISA entry. Citrix has not said how many customers were hit or when exploitation began, and researchers are still testing whether the overflow reaches code execution.
Sources
More in Security
- 01Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394Nozomi Networks says the malware sends traffic that resembles ordinary Google STUN replies, so defenders have to hunt for all-zero transaction IDs instead of blocking an address.
- 02Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted AttacksApple's entry says a crafted file can run code and that exploitation may have hit specific people on iOS versions before iOS 27, but it names no victims and no attacker.
- 03Cloudflare's Open-Source Audit Skill Is at 25,900 Stars, but Its Own Post Shows 20,799 Candidates Became 7,245 Actionable FindingsThe repository trending on GitHub is the 450-line starting point. The funnel numbers in Cloudflare's June write-up describe a different system that has not been released.
- 04FortiMail CVE-2026-104286: Unauthenticated File Write Exploited at Disclosure, With No Fixed Build YetFortinet's advisory FG-IR-26-175 lists fixes for 7.4, 7.6 and 8.0 as pending; the interim steps are disabling IBE and closing the management interface.