NetScaler SAML Deployments Need a Second Upgrade After CVE-2026-88779 Attacks
Citrix fixed NetScaler CVE-2026-88779 SAML memory flaw causing DoS. Check SAML configs and upgrade to 14.1-73.41 or 13.1-64.28 amid active attacks.
Illustrative image generated with AI
Targeted exploitation disrupts customer-managed appliances
Citrix has released fixes for CVE-2026-88779, a memory-overflow vulnerability affecting customer-managed NetScaler ADC and NetScaler Gateway deployments under specific SAML configurations.
Exploitation requires the appliance to operate as either a SAML service provider or a SAML identity provider. Administrators can determine whether that prerequisite is present by checking the configuration for:
- SAML SP:
add authentication samlAction - SAML IdP:
add authentication samlIdPProfile
Citrix said it observed targeted attacks against unmitigated deployments. The impact established by the vendor is denial of service: repeated triggering of the condition can leave the affected service unavailable.
The vendor’s analysis did not identify damage to customer-data integrity. Separate observations have prompted investigation into possible remote code execution, but the available evidence does not confirm successful RCE through CVE-2026-88779.
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities Catalog on October 4, 2026, citing evidence of active exploitation. The KEV listing confirms real-world abuse, independently of the vulnerability’s numerical severity rating.
Which NetScaler versions require an update
The NVD version boundaries and the corrected releases reported as Citrix guidance are:
| Product and branch | Affected version boundary | Corrected release |
|---|---|---|
| NetScaler ADC 14.1 | Before 14.1-73.41 |
14.1-73.41 and later |
| NetScaler Gateway 14.1 | Before 14.1-73.41 |
14.1-73.41 and later |
| NetScaler ADC 13.1 | Before 13.1-64.28 |
13.1-64.28 and later releases of 13.1 |
| NetScaler Gateway 13.1 | Before 13.1-64.28 |
13.1-64.28 and later releases of 13.1 |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.41 FIPS |
14.1-73.41 FIPS and later releases of 14.1-FIPS |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.282 |
13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP |
The reported scope covers customer-managed deployments that satisfy the SAML prerequisite. The supplied information does not establish applicability to other deployment models.
An appliance updated for earlier NetScaler vulnerabilities may still need another upgrade. Systems running 14.1-73.37 were reportedly among those experiencing crashes, while the correction for CVE-2026-88779 begins at 14.1-73.41 on that branch.
Administrators should therefore verify the exact installed build rather than relying on the fact that a recent NetScaler update was applied. They must also check whether either of the relevant SAML configuration entries exists.
Citrix credited Bishop Fox and watchTowr with reporting the vulnerability. WatchTowr reportedly reproduced the flaw, although technical reproduction details were not included in the material available here.
Severity and exploitation are separate measurements
CVE-2026-88779 is classified as CWE-119, or Improper Restriction of Operations within the Bounds of a Memory Buffer. News coverage reports a CVSS score of 8.7; the supplied NVD entry does not include a CVSS vector.
CVSS expresses technical severity. A high score alone does not show that exploitation has occurred.
In this case, the evidence of exploitation comes from CISA’s KEV decision and Citrix’s account of targeted attacks. The available CISA alert does not identify an attacker or explain the exploitation technique.
The vendor-confirmed consequence remains denial of service. Administrators reportedly observed repeated crashes of the nsaaad process, followed by the Pitboss process reaching its restart limit and rebooting the appliance.
Repeated triggering could extend the outage. However, reports of crashes and crafted requests do not by themselves prove code execution.
Suspicious authentication requests raise an unresolved RCE question
Administrators investigating the incidents found authentication usernames containing shell commands. According to BleepingComputer’s account, those commands were intended to retrieve a payload from 213.209.159[.]55, write it to /v, and execute it.
One administrator linked such requests to three nsaaad crash sequences on an appliance and to activity involving multiple SAML authentication factors. The administrator characterized the evidence as attempted exploitation with correlated crashes, not confirmation that the commands ran.
Security researcher Kevin Beaumont separately reported finding a downloaded malware binary running on one patched honeypot. That observation does not establish that CVE-2026-88779 successfully delivered remote code execution against a production appliance.
Another report described a script intended to deploy web shells, remain persistent after reboots, and upload appliance configurations and backups. The user who obtained the script cautioned that there was no proof it had executed.
These observations support investigating possible compromise in addition to installing the update. They do not yet establish RCE as a demonstrated impact of CVE-2026-88779.
What NetScaler operators should do now
Affected organizations should install the corrected release for their product branch. Citrix reportedly recommends deploying the security updates as soon as possible.
A focused response should include the following actions:
- Confirm the installed build. A system on
14.1-73.37does not have the CVE-2026-88779 correction. - Check the SAML prerequisite. Search the configuration for
add authentication samlActionandadd authentication samlIdPProfile. - Review authentication records. Investigate unusual username values containing command syntax or references to downloaded files.
- Examine process and reboot history. Look for repeated
nsaaadcrashes,Pitbossrestart-limit events, and unexpected appliance restarts. - Search historical activity for the reported infrastructure. Requests involving
213.209.159[.]55merit investigation, although their absence cannot prove that no exploitation occurred. - Assess possible compromise before treating patching as complete. The available evidence distinguishes attempted commands from confirmed execution, making forensic review necessary to determine what occurred on a particular appliance.
- Contact Citrix support if the reported behavior is present. Citrix reportedly directed affected customers to its support organization.
Citrix also reportedly provided Global Deny Lists intended to block known malicious IP addresses. The supplied material does not contain those lists or their application procedure, and Citrix continued to recommend installing the corrected software.
Federal agencies face an October 7 deadline
The KEV remediation deadline for CVE-2026-88779 is October 7, 2026. It applies to covered U.S. Federal Civilian Executive Branch agencies, not to every organization using NetScaler.
CISA instructs covered agencies to apply vendor mitigations while complying with BOD 26-04 Prioritizing Security Updates Based on Risk and CISA’s Forensics Triage Requirements. For applicable cloud services, agencies must follow the relevant BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable.
The directive also establishes expectations for determining whether a threat actor compromised a system before the patch was installed. CISA encourages organizations outside the federal scope to prioritize KEV vulnerabilities through risk-based vulnerability management, but the October 7 deadline is not universal.
CVE-2026-88779 follows two other NetScaler flaws added to KEV on September 27, 2026, with federal remediation deadlines of September 30, 2026.
CVE-2026-88771 is a CWE-20 improper input-validation vulnerability rated 9.8, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD says an unauthenticated attacker can execute arbitrary commands.
CVE-2026-88772 is classified as CWE-119 and carries a score of 8.1, with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD describes its possible effects as remote code execution or denial of service.
Their version boundaries included builds before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP, depending on the product branch. CVE-2026-88779 requires later corrected builds, so protection against those earlier flaws does not establish protection against this one.
Other Citrix vulnerabilities entered KEV recently: CVE-2026-19490 on September 9, 2026, and CVE-2026-8452 on August 26, 2026. For current NetScaler deployments, the immediate priorities are the exact software build, the SAML configuration, and evidence of suspicious activity before the upgrade.
Sources
This article is an original reworking based on the sources below.
- primary sourceCISA
- The Hacker News
- BleepingComputer
- SecurityWeek
CVEs covered in this article
- CVE-2026-19490Critical9.8Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- CVE-2026-8452Critical9.8Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
- CVE-2026-88771Critical9.8Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated a
- CVE-2026-88772High8.1Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
- CVE-2026-88778High7.5Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
- CVE-2026-88779High7.5Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.




