Skip to content

Citrix patches exploited NetScaler SAML zero-day (CVE-2026-88779)

Citrix patched CVE-2026-88779, a SAML memory-overflow zero-day in NetScaler ADC/Gateway hitting already-patched appliances. Fix is in 14.1-73.41/13.1-64.28; CISA KEV deadline Oct 7.

Published 3 min read

Citrix has patched a third NetScaler zero-day in under two weeks. CVE-2026-88779 is a memory-overflow flaw (CVSS 8.7) in NetScaler ADC and Gateway configured for SAML, and it was exploited against appliances that had already applied the previous round of fixes. Citrix published advisory CTX697174 after administrators reported fully patched boxes rebooting on Friday; CISA added the CVE to its Known Exploited Vulnerabilities catalog on October 4, with a federal remediation deadline of October 7.

What's affected

Per Citrix's advisory, the bug is reachable only when the appliance acts as a SAML Service Provider or Identity Provider — that is, when the configuration includes an add authentication samlAction (SP) or add authentication samlIdPProfile (IdP) binding. Appliances not using SAML authentication are not exposed.

Fixed builds, from CTX697174:

  • NetScaler ADC / Gateway 14.1 — 14.1-73.41 (and 14.1-73.41 FIPS)
  • NetScaler ADC / Gateway 13.1 — 13.1-64.28
  • 13.1-NDcPP — 13.1-37.282

Versions 13.0 and 12.1 remain end-of-life and receive no fix. Note the build numbers supersede the ones shipped on September 27 for CVE-2026-88771 and CVE-2026-88772 — patching that batch does not cover this one.

Exploitation status

Exploitation is confirmed and predates the patch. Citrix says it observed targeted attacks on unmitigated deployments leading to denial of service; both Kevin Beaumont and watchTowr Labs reported seeing exploitation attempts, including against patched honeypot instances. Citrix classifies CVE-2026-88779 as a DoS issue, but researchers are investigating whether the same memory corruption is exploitable for remote code execution — treat the RCE question as open, not settled.

BleepingComputer, reporting on the honeypot telemetry, described the exploitation pattern: a crafted authentication request carries shell commands in the username field, which fetch and run a downloaded payload. Reported indicators:

213.209.159[.]55   payload host observed in exploitation attempts
/v                  path the downloaded binary is saved to and executed from
nsaaad              process crash observed immediately before exploitation

These are leads from the reporting, not a vendor-published IOC package — pull CTX697174 and your own logs before building detections on them.

Action checklist

  1. If any NetScaler ADC/Gateway runs SAML authentication, upgrade to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS; NDcPP: 13.1-37.282) now. The October 7 CISA deadline is a floor, not a target.
  2. Do not assume last week's patch covered this. Appliances on the September 27 builds were among the ones getting hit.
  3. Hunt for nsaaad crashes in appliance logs and any outbound connection to 213.209.159[.]55, and check for a dropped /v binary.
  4. Anything on 13.0 or 12.1 needs migration, not a patch — there is no fix for EOL branches.
  5. Keep the management interface off the public internet.

Context

This is the third exploited NetScaler zero-day in this cycle, after the CitrixBleed-style CVE-2026-8451 and the September 27 batch led by CVE-2026-88771. The pattern holds: internet-facing, high-value, and attacked within days of each disclosure — this time against the very appliances defenders had just finished patching. If you own a NetScaler edge, assume it stays a live target through the rest of the quarter.

Related stories