Citrix has patched and confirmed in-the-wild exploitation of CVE-2026-88779, an unauthenticated memory overflow in the NetScaler ADC and Gateway SAML handler. CISA added it to the Known Exploited Vulnerabilities catalog on October 4 with a federal remediation deadline of October 7. It is a separate bug from the CVE-2026-88771/88772 pair we covered last week, and it lands on the same product family within days.
What’s vulnerable
CVE-2026-88779 (CWE-119, CVSS 8.7) is triggered by crafted SAML requests sent to appliances configured as a SAML service provider (SP) or identity provider (IdP). Only SAML-configured systems are exposed; appliances using other authentication methods are not affected by this path. A malicious request overflows a memory buffer in the authentication service and crashes it.
Fixed builds:
- NetScaler ADC and Gateway 14.1-73.41 and later
- NetScaler ADC and Gateway 13.1-64.28 and later
- NetScaler ADC 14.1 FIPS 14.1-73.41; 13.1-FIPS and 13.1-NDcPP 13.1-37.282
Anything older on those tracks is vulnerable.
Exploitation
Citrix describes the impact as denial of service: the authentication daemon crashes, which takes down VPN, Gateway and SSO logins for every user behind the appliance. Exploitation was reported as targeted. Whether the flaw reaches code execution is disputed. Norway’s NSM initially flagged potential RCE, and one researcher who obtained an exploit script said it attempts to plant web shells, persist across reboots and exfiltrate appliance configuration and backups. That person cautioned there was no proof the script actually ran. Treat RCE as unconfirmed but plausible given NetScaler’s history with memory-corruption bugs.
The more worrying signal comes from Kevin Beaumont’s honeypots. He reported that patched 13.1 and 14.1 honeypots were crashing under requests from multiple source IPs, and that at least one later ran a downloaded malware binary. Taken together, this suggests exploitation began before the fix shipped and that appliances patched in the previous batch (the September 27 builds) were still exposed. That is the reason for the new fixed-build numbers above.
Impact
Any internet-facing NetScaler Gateway or ADC using SAML authentication is a target. At a minimum an attacker can repeatedly knock out remote access for an entire organization. If the RCE reports hold, this becomes another appliance-foothold bug in the pattern defenders have seen across the CitrixBleed family: edge device compromise, credential and session theft, then lateral movement into the internal network.
Mitigation
- Upgrade to 14.1-73.41, 13.1-64.28 or the FIPS/NDcPP equivalents above. If you patched last week for CVE-2026-88771/88772, you are not yet covered.
- Apply Citrix’s Global Deny List signatures as an interim control where you cannot patch immediately.
- Hunt for crashes. Review
nsaaad/AAA daemon core dumps and unexpected authentication-service restarts since late September; each is a possible exploitation attempt. - Assume compromise on exposed SAML appliances that crashed or show unexpected files in web-served directories, new cron or rc entries, or outbound connections to unfamiliar hosts. Preserve a snapshot, then rebuild from a known-good image and rotate secrets stored on the box (LDAP bind accounts, SAML signing keys, certificates).
- Reduce exposure. Restrict management interfaces to internal networks and put SAML endpoints behind additional filtering where architecture allows.
References
- BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks
- The Hacker News: New NetScaler zero-day exploited in targeted attacks
- SecurityWeek: Exploitation hits appliances patched days earlier
- CISA: Adds Known Exploited Vulnerabilities to Catalog
- Citrix NetScaler security bulletin for CVE-2026-88779 (support.citrix.com)