NEWS

Citrix Discloses Third Actively Exploited NetScaler Zero-Day in Less Than a Week

Citrix's CVE-2026-88779 SAML flaw is the third actively exploited NetScaler zero-day in a week, but a faster vendor response limited the fallout.

Dylan H.

News Desk

October 6, 2026
7 min read
Citrix Discloses Third Actively Exploited NetScaler Zero-Day in Less Than a Week

Citrix's Third NetScaler Zero-Day in a Week

Citrix disclosed CVE-2026-88779 on October 3, 2026, a high-severity SAML memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that is being actively exploited to crash appliances. It is the third actively exploited NetScaler zero-day the vendor has disclosed in under a week, following CVE-2026-88771 and CVE-2026-88772, two critical remote-code-execution flaws patched just days earlier. Unlike the earlier pair, researchers at watchTowr and others consider the new bug's blast radius relatively low, since it only affects appliances configured for SAML authentication rather than every default deployment. Citrix's handling of this disclosure was also notably faster and more consistent than its widely criticized response to the first two flaws.


Details

AttributeValue
CVE IDCVE-2026-88779
DisclosedOctober 3, 2026 (Citrix bulletin CTX697174)
Vulnerability typeMemory overflow / buffer bounds violation (CWE-119)
SeverityHigh — CVSS v4.0 base score 8.7
ImpactDenial of service (no reported impact to data confidentiality/integrity)
Authentication requiredNone (remote, unauthenticated)
Affected configurationNetScaler ADC/Gateway configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP)
Fixed builds14.1-73.41, 13.1-64.28, 14.1-73.41-FIPS, 13.1-37.282-FIPS/NDcPP
CISA KEV statusAdded October 4, 2026; federal remediation deadline October 7, 2026
Credited researchersBishop Fox, watchTowr

How It Happened

A rocky week for NetScaler administrators

The week began with CVE-2026-88771 and CVE-2026-88772, two critical flaws Citrix disclosed only after a chaotic weekend in which network defenders traded warnings on unofficial channels while the vendor stayed publicly silent. CVE-2026-88771, an unauthenticated command-execution bug (CWE-20), affected every NetScaler ADC and Gateway deployment, including default configurations. CVE-2026-88772, a memory overflow bug, required DTLS to be enabled — the out-of-the-box setting for VPN virtual servers. Both carried a CVSS v4.0 score of 9.5, and both were later confirmed exploited for weeks before Citrix's public acknowledgment, with Mandiant and the Google Threat Intelligence Group attributing the activity to a suspected state-backed actor on October 1.

The third flaw emerges

Just days after administrators patched against the first two bugs, Reddit threads and independent researchers began reporting that freshly updated NetScaler appliances were rebooting unexpectedly. According to watchTowr's Jake Knott, exploitation of the new flaw likely began on a Friday. WatchTowr reproduced the issue and confirmed it is a pure denial-of-service bug — it cannot be used for code execution on its own — but noted it can be used to intentionally crash appliances, which may accelerate exploitation of the still-unpatched CVE-2026-88771 on systems that have not yet applied the earlier fix.

A simple, unauthenticated trigger

Knott described the exploit as "incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline," adding that exploitation was "already occurring in the wild" and that disrupting an authentication gateway can block legitimate users from reaching the services behind it. The flaw affects only appliances with SAML SP or IdP profiles configured — a narrower precondition than the two prior bugs, which is why researchers assess its overall impact as lower despite active exploitation.

Citrix's faster response

In contrast to the delayed, largely reactive disclosure of CVE-2026-88771 and CVE-2026-88772 — which drew public criticism from watchTowr's CEO over an "information vacuum" during active exploitation — Citrix alerted customers to the new issue on Friday and followed up the next day, Saturday, with a detailed advisory and a shipped patch. A Citrix spokesperson said the company "immediately developed and published a mitigation while concurrently developing, testing and deploying a fix," and urged "all customers to quickly apply it to their NetScaler instance."


Impact Assessment

Impact AreaDescription
AvailabilityUnauthenticated attackers can crash NetScaler SAML SP/IdP instances with a single crafted request, disrupting authentication gateways and downstream application access
ScopeNarrower than CVE-2026-88771/88772 — only appliances with SAML enabled are affected, not all deployments
Data integrityCitrix states it has found no evidence of impact to customer data integrity from this flaw
Secondary riskRepeated crashing may be used to accelerate exploitation attempts against the still-more-severe CVE-2026-88771 on unpatched appliances
Government exposureCISA KEV entry adds federal remediation pressure (deadline October 7); ASD's ACSC confirmed Australian organizations affected
Cumulative exposureNetScaler ADC/Gateway now account for 18 entries in CISA's KEV catalog as of October 4, 2026, reinforcing the platform's standing as a persistent high-value target

Recommendations

For NetScaler administrators

  • Identify any appliance configured as a SAML Service Provider or SAML Identity Provider and prioritize patching it immediately, even if it was already updated for CVE-2026-88771/88772 in August or September — those earlier builds (14.1-73.37, 13.1-64.23/64.24) do not remediate CVE-2026-88779.
  • Upgrade to 14.1-73.41 or later, 13.1-64.28 or later, or the corresponding FIPS/NDcPP builds.
  • If immediate patching isn't possible, enable Citrix's interim mitigation: Global Deny List signatures delivered through NetScaler Console, with Virtual Patching enabled, on builds between 14.1-73.37 and 13.1-64.23 up to (but not including) the fixed versions.
  • NetScaler 12.x remains end-of-life with no patch available; organizations still running it must upgrade to a supported branch immediately rather than wait on a fix.

For security teams

  • Treat any unexplained NetScaler reboot since late September as a potential exploitation indicator, not just an instability bug — review logs and crash dumps for patterns consistent with the SAML memory overflow.
  • Given that exploitation of CVE-2026-88771 and CVE-2026-88772 reportedly began weeks before public disclosure, conduct forensic review for backdoors, webshells, and unauthorized admin accounts on any appliance that was internet-facing before patches were applied — patching alone does not remove implants planted beforehand.
  • Monitor CISA KEV and vendor advisories for NetScaler closely; three disclosures in one week suggests the investigation into this product line is ongoing and more bulletins may follow.

For end users / downstream organizations

  • Expect possible intermittent outages of SSO/authentication portals that sit behind NetScaler Gateway during this patching window; report repeated login failures to IT rather than assuming local account issues.
  • Follow organizational guidance on password resets or re-authentication if your employer confirms a NetScaler compromise tied to this incident cluster.

Key Takeaways

  1. CVE-2026-88779 is Citrix's third actively exploited NetScaler zero-day disclosed in under a week, following the critical CVE-2026-88771 and CVE-2026-88772 remote-code-execution flaws.
  2. The new flaw is a SAML-specific memory overflow (CVSS v4.0 8.7) causing denial of service, with a narrower blast radius than the prior pair since it requires SAML SP/IdP configuration.
  3. Appliances already patched for the earlier CVEs are still vulnerable and require a second upgrade to 14.1-73.41 / 13.1-64.28 or later.
  4. Citrix's response to this disclosure — alerting customers Friday and shipping a patch Saturday — was markedly faster than its criticized, multi-day-delayed handling of the first two zero-days.
  5. CISA added CVE-2026-88779 to its KEV catalog on October 4, 2026, with a federal remediation deadline of October 7, 2026; Australian organizations have also been affected.
  6. Security teams should treat unexplained NetScaler reboots since late September as potential indicators of compromise and hunt for backdoors predating patch application, not rely on patching alone.

Sources