Citrix patches exploited NetScaler SAML zero-day (CVE-2026-88779)
Citrix patched CVE-2026-88779, a SAML memory-overflow zero-day in NetScaler ADC/Gateway hitting already-patched appliances. Fix is in 14.1-73.41/13.1-64.28; CISA KEV deadline Oct 7.
Citrix has patched a third NetScaler zero-day in under two weeks. CVE-2026-88779 is a memory-overflow flaw (CVSS 8.7) in NetScaler ADC and Gateway configured for SAML, and it was exploited against appliances that had already applied the previous round of fixes. Citrix published advisory CTX697174 after administrators reported fully patched boxes rebooting on Friday; CISA added the CVE to its Known Exploited Vulnerabilities catalog on October 4, with a federal remediation deadline of October 7.
What's affected
Per Citrix's advisory, the bug is reachable only when the appliance acts as a SAML Service Provider or Identity Provider — that is, when the configuration includes an add authentication samlAction (SP) or add authentication samlIdPProfile (IdP) binding. Appliances not using SAML authentication are not exposed.
Fixed builds, from CTX697174:
- NetScaler ADC / Gateway 14.1 — 14.1-73.41 (and 14.1-73.41 FIPS)
- NetScaler ADC / Gateway 13.1 — 13.1-64.28
- 13.1-NDcPP — 13.1-37.282
Versions 13.0 and 12.1 remain end-of-life and receive no fix. Note the build numbers supersede the ones shipped on September 27 for CVE-2026-88771 and CVE-2026-88772 — patching that batch does not cover this one.
Exploitation status
Exploitation is confirmed and predates the patch. Citrix says it observed targeted attacks on unmitigated deployments leading to denial of service; both Kevin Beaumont and watchTowr Labs reported seeing exploitation attempts, including against patched honeypot instances. Citrix classifies CVE-2026-88779 as a DoS issue, but researchers are investigating whether the same memory corruption is exploitable for remote code execution — treat the RCE question as open, not settled.
BleepingComputer, reporting on the honeypot telemetry, described the exploitation pattern: a crafted authentication request carries shell commands in the username field, which fetch and run a downloaded payload. Reported indicators:
213.209.159[.]55 payload host observed in exploitation attempts
/v path the downloaded binary is saved to and executed from
nsaaad process crash observed immediately before exploitation
These are leads from the reporting, not a vendor-published IOC package — pull CTX697174 and your own logs before building detections on them.
Action checklist
- If any NetScaler ADC/Gateway runs SAML authentication, upgrade to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS; NDcPP: 13.1-37.282) now. The October 7 CISA deadline is a floor, not a target.
- Do not assume last week's patch covered this. Appliances on the September 27 builds were among the ones getting hit.
- Hunt for
nsaaadcrashes in appliance logs and any outbound connection to 213.209.159[.]55, and check for a dropped/vbinary. - Anything on 13.0 or 12.1 needs migration, not a patch — there is no fix for EOL branches.
- Keep the management interface off the public internet.
Context
This is the third exploited NetScaler zero-day in this cycle, after the CitrixBleed-style CVE-2026-8451 and the September 27 batch led by CVE-2026-88771. The pattern holds: internet-facing, high-value, and attacked within days of each disclosure — this time against the very appliances defenders had just finished patching. If you own a NetScaler edge, assume it stays a live target through the rest of the quarter.