Technology·News & analysis
Citrix rushes out patches for another NetScaler zero-day as attackers crash appliances
A new flaw in NetScaler's SAML login feature is being exploited to knock appliances offline, weeks after two other zero-days. Admins who just patched have to patch again.

Tide
Ripple
Sci-fi
1/10
Reality
Shipping
One crafted login request, and the corporate front door falls over.How we rate
Attackers are exploiting another Citrix NetScaler zero-day, this time to crash the login gateways that companies use for remote access.
Citrix has released fixed versions, and CISA ordered federal agencies to patch by Wednesday. If your organization uses NetScaler with SAML single sign-on, it needs to upgrade again, even if it just patched.
What to know
- Citrix released fixes for CVE-2026-88779, a memory overflow flaw in NetScaler ADC and Gateway that attackers have exploited to cause denial of service.
- It only affects appliances set up for SAML single sign-on, as a service provider or identity provider, with Gateway or AAA features.
- CISA added it to its list of known exploited flaws and gave US federal agencies until Wednesday, October 7, to patch.
- Admins who just patched two earlier NetScaler zero-days must upgrade again, and researchers are checking whether the new bug allows code execution.
Citrix NetScaler admins are having a terrible few weeks. Attackers are exploiting yet another zero-day in the popular remote-access appliances, and Citrix has released emergency fixes for it.
The new flaw, CVE-2026-88779, lets attackers crash NetScaler gateways that handle single sign-on logins.
What's the vulnerability?
CVE-2026-88779 is a memory overflow bug in NetScaler ADC and NetScaler Gateway. Citrix rates it 8.7 out of 10, BleepingComputer reports.
"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company said, as quoted by BleepingComputer. "If the condition is triggered repeatedly, the service may remain unavailable."
Easy to trigger: "This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline," Jake Knott, head of threat intelligence at watchTowr, told The Register.
Why it hurts: "Disrupting an authentication gateway can prevent legitimate users from accessing the services behind it," Knott said.
Who is affected?
Only appliances using SAML, a standard for single sign-on logins. The flaw affects on-premises NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, together with Gateway or AAA functionality, Help Net Security reports.
Affected versions, according to Help Net Security:
- NetScaler ADC and Gateway 14.1 before 14.1-73.41
- NetScaler ADC and Gateway 13.1 before 13.1-64.28
- NetScaler ADC FIPS before 14.1-73.41 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.282
What should admins do?
Upgrade now. Citrix released fixed builds early Sunday: NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28, BleepingComputer reports. FIPS customers should move to 14.1-73.41 FIPS, and FIPS and NDcPP customers on 13.1 should install 13.1-37.282.
Upgrade again, even if you just did. Organizations that recently patched the earlier NetScaler flaws must upgrade a second time. "If you upgraded your NetScaler deployment with one of the updated software releases identified in the security bulletin for CVE 2026-88771 through CVE 2026-88778, and if you have determined that your NetScaler deployment meets the preconditions described above, please upgrade your deployment again," Citrix warned.
Can't upgrade yet? Citrix has an interim mitigation and Global Deny List signatures that block known malicious IP addresses, but still recommends installing the update as soon as possible.
Prioritize the right boxes: "Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix's interim mitigation if an immediate upgrade is not possible," Knott told The Register.
Check for compromise: Citrix provides a script through NetScaler Console to look for signs of compromise. "A clean result is not definitive proof," Knott warned. WatchTowr also notes the latest version can report a false positive about suspicious "nobody" processes, so admins should review results carefully and preserve evidence before updating, Help Net Security reports.
How was it discovered?
Through crashing appliances.
The attacks were first noticed on Thursday, when NetScaler admins reported that recently patched appliances were unexpectedly rebooting, BleepingComputer reports. In a Reddit thread, one admin said multiple customers on NetScaler 14.1-73.37 saw repeated forced reboots despite having the latest updates.
Others reported the same pattern, even on appliances rebuilt from fresh images. One thread described the authentication process, nsaaad, crashing repeatedly until a monitoring process hit its restart limit and rebooted the whole appliance.
Citrix responds: late Friday, Citrix said it was investigating a "newly observed issue related to SAML authentication in customer-managed NetScaler deployments," The Register reports. It published a security bulletin with fixes on October 3, according to Tenable.
"After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix," a Citrix spokesperson told The Register.
Citrix credited watchTowr and Bishop Fox with helping it address the issue. Citrix also confirmed the problem was different from the previously disclosed NetScaler vulnerabilities, and advised customers seeing it to contact Citrix support, BleepingComputer reports.
Quiet on details: Citrix didn't answer The Register's questions about how many appliances have been affected or what attackers are doing after exploiting the bug, but urged customers to "quickly apply" the fix.
Is it only a crash, or worse?
That's still unclear.
Citrix's view: "Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data," the company said.
What admins saw: one administrator investigating crashes on 14.1-73.37 devices found login usernames containing shell commands that would download a file from a remote server, save it and run it, BleepingComputer reports. The requests appeared right before confirmed crash sequences, but the admin stressed the logs didn't confirm the commands actually ran.
Honeypot hits: security researcher Kevin Beaumont reported attacks on his honeypots from multiple IP addresses and said he found a downloaded malware binary on one, according to Help Net Security. Attackers appear to be trying to install webshells.
"So on one of the honeypots it's running a downloaded (malware) binary. Both were patched, so new vuln," Beaumont said, according to BleepingComputer. "It's being sprayed and prayed. One of the honeypots doesn't even have a valid SSL certificate as I let it expire."
History repeating? Beaumont noted that Citrix described the flaw as a "memory overflow vulnerability leading to Denial of Service," the same way an earlier bug, CVE-2025-6543, was first described before later attacks showed it could be used for remote code execution, BleepingComputer reports. He has called the activity potentially another "PitScaler" vulnerability.
Not yet public: watchTowr reproduced the flaw after investigating reports of honeypot activity, but hasn't shared technical details, BleepingComputer and Help Net Security report.
Detection help: a threat hunter at insurance company Geico has shared a detection rule, written in the SIGMA format, for spotting probing, scanning and exploitation attempts, Help Net Security reports.
Researchers are still investigating whether the flaw can be used for remote code execution, BleepingComputer reports.
What did CISA do?
The US Cybersecurity and Infrastructure Security Agency confirmed on Sunday that CVE-2026-88779 is under active exploitation and added it to its Known Exploited Vulnerabilities catalog, The Register and Help Net Security report.
CISA ordered US federal civilian agencies to fix the flaw by Wednesday, October 7, and to check for compromise.
How does this connect to the earlier zero-days?
It's the latest in a run of NetScaler problems.
On September 27, Citrix disclosed eight vulnerabilities, weeks after attackers began abusing two of them, CVE-2026-88771 and CVE-2026-88772, The Register reports. Tenable says those two were zero-day remote code execution flaws.
The new bug isn't technically related, The Register notes. But watchTowr researchers suspect attackers have used it to crash machines on purpose, to make exploiting CVE-2026-88771 faster.
What it means for you
- If you run NetScaler with SAML: upgrade to the fixed builds now, even if you patched last week, then run Citrix's compromise check.
- If you use a company VPN or remote login: brief outages at your organization's login gateway may be related, and IT teams may need emergency maintenance windows.
- Everyone else: another reminder that internet-facing gateways are prime targets, and patches sometimes come in waves.
The bottom line
Attackers are exploiting a new Citrix NetScaler zero-day to crash SAML login gateways, and researchers are probing whether it allows more than that. Citrix has fixes out, CISA wants federal agencies patched by Wednesday, and admins who just patched the earlier zero-days have to do it all over again.
Key facts
- Vulnerability
- CVE-2026-88779, memory overflow, CVSS 8.7
- Affected
- NetScaler ADC and Gateway with SAML authentication
- Fixed versions
- 14.1-73.41 and 13.1-64.28 (plus FIPS builds)
- Impact
- Denial of service; code execution under investigation
- CISA deadline
- October 7, 2026 for US federal agencies
Got questions?
Quick answers, plain wordsWhat is CVE-2026-88779?
A memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can be triggered to crash the appliance, causing a denial of service. Citrix rates it 8.7 out of 10.
Is it being exploited?
Yes. Citrix says it has observed targeted attacks on unmitigated NetScaler deployments, and CISA has added it to its Known Exploited Vulnerabilities catalog.
Who is affected?
Only on-premises NetScaler ADC and Gateway appliances configured for SAML authentication, as a service provider or identity provider, together with Gateway or AAA functionality.
Which versions fix it?
NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28. FIPS customers should install 14.1-73.41 FIPS, and FIPS and NDcPP customers on 13.1 should install 13.1-37.282, according to BleepingComputer.
I just patched NetScaler. Am I safe?
Not necessarily. Citrix says customers who upgraded to fix CVE-2026-88771 through CVE-2026-88778 should upgrade again if they use SAML.
Can attackers run code with it?
Citrix describes it as a denial-of-service flaw and says it hasn't seen an impact on customer data. But some admins and researchers have seen activity suggesting attackers are trying to run commands, and that's still being investigated.
What if I can't upgrade right away?
Citrix offers an interim mitigation and Global Deny List signatures that block known malicious IP addresses, but recommends installing the update as soon as possible.
How do I check for compromise?
Citrix provides an indicator-of-compromise script through NetScaler Console. WatchTowr notes a clean result isn't definitive proof, and the latest version can flag false positives.
Is this related to the earlier NetScaler zero-days?
Not technically. But watchTowr researchers suspect attackers used it to crash machines on purpose to speed up exploitation of the earlier CVE-2026-88771, The Register reports.
SourcesCitrix security bulletin
Topics and tagsCybersecurity, citrix, netscaler, zero day
Related stories

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers
Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

A Pentagon records system was breached for 9 months before anyone noticed
The Defense Manpower Data Center disclosed that unauthorized users accessed unencrypted personal data on 2.76 million living and 294,000 deceased people between October 2025 and July 2026.

Apple patches a zero-day flaw already used in 'extremely sophisticated' targeted attacks
Apple fixed CVE-2026-86950, a CoreGraphics flaw reported by Meta and already exploited against specific targeted individuals, in its seventh zero-day patch of 2026.
More in brief
- Schneider Electric agrees to buy PTC for $22.6 billion in its biggest deal everOct 6
- A researcher found the same AI agent flaw at Google, Rapid7 and more. He calls it 'protocol pivoting'Oct 5
- Lucid's production drops to its lowest level since early 2025 as it sells off unsold carsOct 5
- Google says some Android apps need extra work to run well on Intel GooglebooksOct 5
- Utah lets an AI write first-time acne prescriptions, a US firstOct 5
- Reflection unveils Beam, an open-weight AI model it pitches as the West's answer to Chinese labsOct 5