Citrix's Third NetScaler Zero-Day in Five Weeks Hits Appliances Patched Days Earlier
Citrix has confirmed that CVE-2026-88779, a newly disclosed NetScaler zero-day, was actively exploited against NetScaler ADC and NetScaler Gateway appliances that administrators had just patched days earlier for two unrelated zero-days, CVE-2026-88771 and CVE-2026-88772. The new flaw is an unauthenticated memory overflow (CWE-119) affecting appliances configured as a SAML Service Provider or Identity Provider, carries a CVSS v4.0 score of 8.7, and crashes the authentication service — knocking VPN and SSO access offline organization-wide. Citrix shipped fixed builds on October 4, 2026, and the Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities (KEV) catalog that same day, giving U.S. federal agencies until October 7 to remediate. It is the third actively-exploited NetScaler zero-day Citrix has disclosed in roughly five weeks.
Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-88779 |
| Vendor / Product | Citrix NetScaler ADC, NetScaler Gateway |
| Vulnerability Type | Unauthenticated memory overflow (CWE-119) |
| CVSS v4.0 Score | 8.7 (High) |
| Preconditions | Appliance configured as SAML Service Provider or SAML Identity Provider |
| Citrix Classification | Denial-of-Service — contested; Norway's NSM suspects possible RCE |
| Related Flaws | CVE-2026-88771, CVE-2026-88772 (patched September 29, 2026) |
| Fixed Builds | NetScaler ADC/Gateway 14.1-73.41, 13.1-64.28; FIPS/NDcPP 14.1-73.41 FIPS, 13.1-37.282 |
| Citrix Bulletin | CTX697174 (separate from the earlier CTX697096 bulletin) |
| CISA KEV | Added October 4, 2026; federal remediation deadline October 7, 2026 |
| Credited Researchers | Bishop Fox, watchTowr |
Three Zero-Days, One Punishing Patch Cycle
On September 29, 2026, Citrix shipped emergency fixes for CVE-2026-88771 and CVE-2026-88772, a pair of pre-authentication NetScaler flaws that Mandiant later said had already been under active exploitation by suspected state-sponsored actors for weeks. Administrators raced to apply that patch — and then, within days, many of the very same appliances began rebooting unexpectedly. Citrix traced the new crashes to a separate, unrelated vulnerability living in the SAML authentication handler rather than the code paths closed by the September 29 bulletin. Citrix's new advisory, tracked under support article CTX697174, explicitly tells customers who upgraded under the earlier CTX697096 bulletin that they must upgrade again: patching for CVE-2026-88771/CVE-2026-88772 does nothing to address CVE-2026-88779. For security teams who had just closed out one NetScaler emergency, the timing made clear this was a distinct, unrelated bug — not a bypass of the prior fix.
"Sprayed and Prayed": What Researchers Saw in the Wild
Security researcher Kevin Beaumont said he observed a downloaded malware binary executing on one of his honeypots — notably, a honeypot that was already running a fully patched NetScaler build, which he flagged as evidence this was a genuinely new vulnerability rather than a known one slipping through. Beaumont characterized the wave of activity as attackers "being sprayed and prayed," language that matches Citrix's own description of broad, opportunistic scanning from numerous source IP addresses rather than one tightly coordinated campaign. Citrix credited Bishop Fox and watchTowr for their assistance investigating the issue; watchTowr separately said it reproduced the vulnerability within hours of spotting the honeypot activity, though it withheld technical exploitation details to avoid handing attackers a roadmap.
Administrators and researchers reported malicious SAML authentication requests carrying shell commands hidden inside the username field, attempting to download additional payloads. A researcher who obtained a copy of an attacker's follow-on script said it attempted to plant web shells, establish persistence that could survive a reboot, and exfiltrate the appliance's configuration and backup files — though they cautioned there was no confirmed evidence the script had actually executed successfully on a target.
DoS Officially — RCE Still an Open Question
Citrix's own position has not changed: "This issue affects service availability, and we have not identified an impact on the integrity of customer data." The company classifies CVE-2026-88779 strictly as a denial-of-service bug that repeatedly crashes the nsaaad authentication process until the Pitboss watchdog forces a full appliance reboot. Norway's national security authority, NSM, has offered a differing read, flagging the possibility that the same memory-overflow primitive could be pushed toward remote code execution rather than a crash alone. As of publication, Citrix has not confirmed RCE, and the gap between the vendor's DoS classification and researchers' more cautious "we're not ruling it out yet" stance remains unresolved.
Impact Assessment
| Impact Area | Description |
|---|---|
| Availability | Repeated crashes of the nsaaad process force full appliance reboots via the Pitboss watchdog, cutting off VPN/SSO org-wide |
| Repeat Exposure | Appliances patched September 29 for CVE-2026-88771/CVE-2026-88772 were hit again days later by this separate, unrelated flaw |
| Pattern of Exploitation | Third actively-exploited NetScaler zero-day Citrix has disclosed in roughly five weeks |
| Data Integrity | Citrix states no identified impact on customer data integrity; attacker scripts reportedly attempted config/backup exfiltration, success unconfirmed |
| Scope of Attacks | Described by Citrix and Beaumont as broad, opportunistic ("sprayed and prayed") scanning rather than a single narrow campaign |
| Compliance / Federal | CISA KEV listing (added October 4) sets a binding October 7, 2026 deadline for U.S. federal agencies; sixth NetScaler CVE added to KEV in 2026 |
Recommendations
For NetScaler Administrators
- Upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 (FIPS/NDcPP) immediately — even if the appliance was already patched under the September 29 CTX697096 bulletin for CVE-2026-88771/CVE-2026-88772.
- Confirm exposure by checking the running configuration for
add authentication samlAction(SAML SP) oradd authentication samlIdPProfile(SAML IdP). - Apply Citrix's Global Deny List signatures as an interim mitigation on any appliance that cannot be patched immediately.
- Treat any unexpected reboot or repeated
nsaaadcrash since October 1–2, 2026 as a potential indicator of exploitation, regardless of current patch level.
For Security Teams
- Run a compromise assessment — not just a patch — on any internet-exposed, SAML-enabled NetScaler appliance that showed crash or reboot activity in this window.
- Hunt for authentication requests containing shell-command-like strings in the username field, unexpected web-shell artifacts, and unplanned access to configuration or backup files.
- Treat the recurring pattern (three zero-days in roughly five weeks) as a signal to increase monitoring cadence on edge appliances, which typically sit outside normal EDR coverage.
- Track Citrix's CTX697174 bulletin and the CISA KEV entry for updates, since the DoS-versus-RCE classification may change as researcher analysis continues.
For Leadership / Downstream Organizations
- If remote access depends on a third-party or MSSP-managed NetScaler Gateway, confirm with that provider that the fix applied is specifically for CVE-2026-88779, not just the earlier September 29 batch.
- Expect possible short service interruptions to VPN/SSO portals while providers patch and, where needed, reboot affected gateways.
- Factor the repeated NetScaler disclosures into vendor-risk and architecture reviews — three zero-days in five weeks on the same edge platform is a pattern worth budgeting against, not an isolated incident.
Key Takeaways
- CVE-2026-88779 is an unauthenticated memory overflow (CWE-119) in SAML-configured NetScaler ADC/Gateway deployments, CVSS v4.0 8.7, fixed in 14.1-73.41 / 13.1-64.28 (plus FIPS/NDcPP builds).
- It is the third actively-exploited NetScaler zero-day Citrix has disclosed in roughly five weeks, following CVE-2026-88771 and CVE-2026-88772.
- Attacks hit appliances that had been patched just days earlier for those two prior flaws — Citrix explicitly warned admins they must upgrade again under the separate CTX697174 bulletin.
- Citrix classifies the bug strictly as denial-of-service; Norway's NSM and some researchers suspect possible remote code execution, a question still unresolved as of publication.
- Researcher Kevin Beaumont observed malware binaries executing on fully patched honeypots and described the exploitation wave as attackers being "sprayed and prayed."
- CISA added the CVE to its KEV catalog on October 4, 2026, with an October 7 federal remediation deadline — the sixth NetScaler entry added to the catalog in 2026.