Citrix patches new NetScaler zero-day as attackers crash appliances patched days earlier
Citrix released emergency builds for CVE-2026-88779, a memory overflow in NetScaler SAML deployments that attackers are using to knock appliances offline.
At a glance
- Citrix shipped NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 on 4 October to fix CVE-2026-88779, rated CVSS 8.7.
- Only deployments configured as a SAML service provider or SAML identity provider are exposed, according to Citrix.
- CISA listed the flaw in its Known Exploited Vulnerabilities catalog on 4 October with a 7 October remediation deadline for federal agencies.
- Administrators reported forced reboots on appliances already patched against CVE-2026-88771 and CVE-2026-88772.
Citrix released emergency NetScaler builds on 4 October to close CVE-2026-88779, a memory overflow flaw that attackers are already using to knock NetScaler ADC and Gateway appliances offline — in several cases appliances that administrators had patched only days earlier against a separate pair of zero-days. CISA has added the bug to its Known Exploited Vulnerabilities catalog with a 7 October remediation deadline for US federal agencies, and The Record reported that US and Australian authorities both issued advisories urging operators to act.
What happened
According to BleepingComputer, Citrix's advisory describes the problem as targeted attacks on unmitigated NetScaler deployments that can lead to denial of service, and assigns it a CVSS score of 8.7. SecurityWeek reported that Citrix also warns the service may stay unavailable if the condition is triggered repeatedly.
The flaw surfaced because of its symptoms rather than a disclosure. SecurityWeek reported that NetScaler administrators began describing unexpected forced reboots on systems they had already fully patched, which pointed to something new rather than lingering exploitation of the earlier bugs. Researcher Kevin Beaumont concluded a new vulnerability was in play after malware was pulled onto his honeypots despite both earlier flaws being fixed, BleepingComputer reported.
Technical details
Help Net Security reported that exploitation requires SAML authentication configured with Gateway or AAA functionality on on-premises deployments, and credited Bishop Fox and watchTowr with identifying the flaw. The same report lists the affected branches as NetScaler ADC and Gateway 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, NetScaler ADC FIPS before 14.1-73.41 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.282.
BleepingComputer reported that defenders found crafted authentication usernames carrying shell commands that attempted to fetch a payload from the address 213.209.159[.]55. Help Net Security reported that attackers were seen trying to download and run scripts to install a web shell, while whether the flaw actually yields remote code execution remains unclear. In an update to its story, SecurityWeek said watchTowr assessed CVE-2026-88779 as a denial-of-service issue only, possibly used to crash appliances before the earlier zero-days were exploited.
Who is affected
On-premises NetScaler ADC and Gateway appliances that terminate SAML authentication are the exposed population — a configuration common in enterprise and public-sector remote access. SecurityWeek noted this is the sixth exploited NetScaler vulnerability CISA has catalogued in 2026, and that the previous round of emergency patching pushed some organisations to temporarily disconnect their appliances altogether.
What to do
Upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 depending on the branch in use. Help Net Security reported that Citrix also points operators to Global Deny List signatures and to compromise-checking scripts that can be run from NetScaler Console. Because the earlier zero-days were exploited before patches existed, treat an upgrade as insufficient on its own: review SAML authentication logs for malformed usernames, look for unexplained reboots, and hunt outbound connections to the address reported by BleepingComputer.
Related CVEs
Sources
- Citrix patches NetScaler SAML zero-day exploited in attacks — BleepingComputer
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier — SecurityWeek
- CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) — Help Net Security
- US, Australia warn of latest Citrix vulnerability after NetScaler advisory — The Record
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



