A NetScaler SAML vulnerability is being exploited against Citrix appliances that administrators had already patched days earlier. Citrix published a bulletin for CVE-2026-88779 on 3 October 2026, rating it 8.7 out of 10, and told customers who upgraded for the late-September flaws to upgrade again. The United States cyber agency set a remediation deadline of 7 October 2026 for federal bodies.

What the Flaw Does

CVE-2026-88779 lets an unauthenticated attacker crash a NetScaler appliance over the network, with no user interaction required. Citrix describes it as a “memory overflow vulnerability leading to Denial of Service” and classifies it as CWE-119, an improper restriction of operations within the bounds of a memory buffer. A denial of service makes a system unavailable rather than handing over control of it.

It only applies where the appliance is configured as a SAML Service Provider or a SAML Identity Provider. SAML is the standard that lets a user sign in once and reach several applications; a Service Provider is the application trusting the sign-in, and an Identity Provider is the system performing it. Appliances not configured for either role are outside the stated preconditions.

In exploitation, the nsaaad authentication process crashes repeatedly until NetScaler’s Pitboss supervisor reaches its restart limit and reboots the appliance. BleepingComputer reported one administrator documenting three confirmed crash sequences on a single appliance alongside exploitation attempts. Citrix rates the issue 8.7 on the CVSS version 4.0 scale, with the vector string published in Citrix’s bulletin CTX697174 showing high availability impact and no confidentiality or integrity impact.

Citrix says its own managed cloud services are not affected, because Cloud Software Group upgrades those itself. The work, and its cost in maintenance windows, falls on customer-managed deployments.

Which Builds Close Which Flaw

The build that fixed the September flaws does not fix this one. Citrix issued two sets of fixed versions six days apart, and the difference is a matter of a few build numbers.

BranchFixes CVE-2026-88771 and CVE-2026-88772 (27 September 2026)Fixes CVE-2026-88779 (3 October 2026)
NetScaler ADC and Gateway 14.114.1-73.37 and later14.1-73.41 and later
NetScaler ADC and Gateway 13.113.1-64.23 and later13.1-64.28 and later
NetScaler ADC 14.1 FIPS14.1-73.37 FIPS and later14.1-73.41 FIPS and later
NetScaler ADC 13.1 FIPS and NDcPP13.1-37.279 and later13.1-37.282 and later

FIPS and NDcPP are separately certified builds used where procurement rules require them, which is why they carry their own version numbers. Organisations on those branches cannot take the standard build.

Reporting on the September patches also noted a caveat on the 13.1 branch: where the command show ns variable returns any variables, Citrix directed administrators to 13.1-64.24 rather than 13.1-64.23 to avoid a reboot loop during the upgrade. Whether a comparable caveat applies to the 13.1-64.28 build has not been stated publicly.

Why a Late-September Patch Is Not Enough

An organisation that patched on 27 September is running 14.1-73.37 or 13.1-64.23 and is still exposed to CVE-2026-88779. Citrix explicitly warned customers who had upgraded to address CVE-2026-88771 through CVE-2026-88778 that they must upgrade the deployment again.

That is what makes this case unusual. Exploitation did not hit unpatched laggards; it hit appliances that had just been through an emergency maintenance window. SecurityWeek reported administrators working through the weekend of 3 and 4 October after exploitation began.

Our earlier report on the September NetScaler zero-days set out the compromise checks for that round. Those checks do not cover this flaw, and Citrix has published no mitigation for CVE-2026-88779 other than upgrading.

The CISA Deadline and Who It Binds

The United States Cybersecurity and Infrastructure Security Agency, the federal body that directs civilian agencies on cyber defence, added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on 4 October 2026 with a due date of 7 October 2026. The catalog lists flaws confirmed as exploited in the wild.

  • CVE-2026-88771: added 27 September 2026, due 30 September 2026, described as allowing an unauthenticated attacker to execute arbitrary commands.
  • CVE-2026-88772: added 27 September 2026, due 30 September 2026, described as allowing remote code execution or denial of service.
  • CVE-2026-88779: added 4 October 2026, due 7 October 2026, described as allowing a denial of service.

The required action, per CISA’s catalog entry, is to apply vendor mitigations under Binding Operational Directive 26-04 guidance, or discontinue use of the product if none is available. A Binding Operational Directive is a compulsory instruction to United States federal civilian executive branch agencies. It does not bind private companies or organisations outside the United States, which face no legal deadline, though the catalog is widely used as a prioritisation list.

Whether It Allows Code Execution Is Disputed

Citrix describes the flaw as denial of service only, and researchers disagree about whether more is possible. The disagreement is unresolved as of 5 October 2026.

WatchTowr, the firm that published research on the September flaws, concluded that CVE-2026-88779 is a denial-of-service bug that can only be used to crash systems, according to SecurityWeek. WatchTowr suggested attackers crashed machines deliberately in order to speed up exploitation of the earlier CVE-2026-88771.

Against that, BleepingComputer reported an administrator observing crafted authentication usernames containing shell commands that fetched a payload from an external address and ran it, and the researcher Kevin Beaumont reporting that one of his honeypots ran a downloaded binary while patched. Those are individual observations rather than confirmed analysis, and the two accounts of WatchTowr’s position differ between outlets. Citrix has not revised its description.

What Is Not Known

Several points remain open, and nothing here should be read as a complete picture of exposure.

  • Who is behind the attacks: no outlet reviewed for this report named a group, and Citrix has not attributed the activity.
  • How many appliances are exposed: no scanning organisation’s count for this flaw was published in the coverage reviewed.
  • Whether code execution is possible: see above; the vendor says no, individual observations suggest otherwise.
  • Whether the 13.1 reboot-loop caveat still applies: Citrix has not restated it for the new build.

For comparison on how these deadlines work in practice, our report on a WordPress flaw given a CISA deadline in September set out the same mechanism on a different product.

Frequently Asked Questions

What Is the NetScaler SAML Vulnerability?

CVE-2026-88779, a memory overflow flaw in customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Service Provider or Identity Provider. Citrix published the bulletin on 3 October 2026 and rates it 8.7 on the CVSS version 4.0 scale. It causes a denial of service by crashing the appliance.

Which Version Fixes It?

14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282, depending on the branch. The builds released on 27 September 2026 for the earlier flaws do not fix this one.

Is It Enough to Have Patched in September?

No. Citrix told customers who upgraded to address CVE-2026-88771 through CVE-2026-88778 that they must upgrade again, and exploitation has been reported against appliances patched days earlier.

What Is the CISA Deadline?

7 October 2026. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on 4 October 2026. The deadline binds United States federal civilian executive branch agencies under Binding Operational Directive 26-04; it is not a legal requirement for private organisations or bodies outside the United States.

Does It Allow an Attacker to Run Code?

Citrix says the impact is denial of service, and its published CVSS vector records no confidentiality or integrity impact. Individual administrator and researcher observations reported by BleepingComputer point to payload execution, while WatchTowr’s assessment as reported by SecurityWeek is that it can only crash systems. The question is unsettled as of 5 October 2026.

Are Citrix Cloud Services Affected?

Citrix says its managed cloud services are not affected, because Cloud Software Group upgrades them. The bulletin applies to customer-managed appliances.