zero-day • BleepingComputer

Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 Exploited in Attacks

Citrix has released emergency updates for a new NetScaler [zero-day](/wiki/zero-day.html "Zero-day") tracked as CVE-2026-88779 that is already being exploited in targeted attacks. The flaw is a memory buffer issue in SAML authentication (Security Assertion Markup Language, a standard protocol for federated sign-in) on NetScaler ADC and NetScaler Gateway appliances when Gateway or AAA features are enabled.

Citrix Patches NetScaler SAML Zero-Day CVE-2026-88779 Exploited in Attacks

Citrix has released emergency updates for a new NetScaler zero-day tracked as CVE-2026-88779 that is already being exploited in targeted attacks. The flaw is a memory buffer issue in SAML authentication (Security Assertion Markup Language, a standard protocol for federated sign-in) on NetScaler ADC and NetScaler Gateway appliances when Gateway or AAA features are enabled. Citrix scores it CVSS 8.7 and describes denial-of-service (DoS) impact: if the condition is triggered repeatedly, the service may remain unavailable. At the same time, administrators and researchers report activity suggesting the same bug may enable remote code execution.

The attacks surfaced Thursday and Friday, 1–2 October 2026, only days after organisations patched two other actively exploited NetScaler flaws (CVE-2026-88771 and CVE-2026-88772). Reddit threads described recently patched 14.1-73.37 appliances forced into reboots despite running the then-latest security release. The `nsaaad` process crashed repeatedly until Pitboss hit its restart limit and rebooted the appliance. Security researcher Kevin Beaumont — who previously coined "PitScaler" — saw the same crashes against patched honeypots and later found one honeypot running a downloaded malware binary, pointing beyond pure DoS.

Citrix first confirmed on Friday that engineering was tracking a "newly observed issue" tied to SAML, distinct from the earlier CVEs. Early Sunday morning, 4 October, Citrix shipped NetScaler ADC/Gateway 14.1-73.41 and 13.1-64.28. FIPS customers should move to 14.1-73.41 FIPS; 13.1 FIPS/NDcPP customers to 13.1-37.282. The same day, CISA (the U.S. Cybersecurity and Infrastructure Security Agency) added CVE-2026-88779 to its KEV catalog — Known Exploited Vulnerabilities — with a 7 October 2026 remediation deadline for federal civilian agencies. It is the sixth exploited NetScaler vulnerability CISA listed in 2026.

The vulnerability applies when the appliance is configured as a SAML SP (`add authentication samlAction`) or SAML IdP (`add authentication samlIdPProfile`). Citrix says it has observed targeted attacks on unmitigated deployments and offers Global Deny Lists against known malicious IPs, but urges installing the security updates as soon as possible. Organisations that just upgraded for CVE-2026-88771 through 88778 must upgrade again if the SAML preconditions apply.

Administrators investigating crashes reported crafted authentication usernames containing shell commands that download a payload from addresses including 213.209.159.55, save it as `/v`, and attempt execution — immediately before confirmed `nsaaad` crash sequences. That shows exploitation attempts; it does not always prove successful command execution. watchTowr Labs reproduced the vulnerability after honeypot reports. The pattern echoes CVE-2025-6543, first framed as DoS before later attacks demonstrated RCE.

For Nordic and European organisations relying on NetScaler as a VPN gateway or federated login edge, the risk is concrete: authentication outages can halt remote work, and if RCE is confirmed at scale the appliance becomes initial access for lateral movement. NetScaler has been a recurring target this year, making rapid patching and forensic triage the priority over wait-and-see.

What IT and security leads should do now

Upgrade immediately to 14.1-73.41 or 13.1-64.28 (and matching FIPS/NDcPP builds). Confirm whether SAML SP/IdP is configured. Review `nsaaad`/Pitboss crashes, suspicious SAML requests, and unexpected downloads or binaries on the appliance. Treat suspected compromise as full appliance compromise: rotate secrets, review connected systems, and follow forensic triage under CISA BOD 26-04 where applicable. Deny lists can supplement — they do not replace the patch.

Sources & References

← All News Tools