Third Exploited NetScaler Zero-Day in a Week: CVE-2026-88779 Crashes SAML-Configured Appliances — Including Boxes Patched Days Earlier — CISA Deadline October 7

Third Exploited NetScaler Zero-Day in a Week: CVE-2026-88779 Crashes SAML-Configured Appliances — Including Boxes Patched Days Earlier — CISA Deadline October 7

Third Exploited NetScaler Zero-Day in a Week: CVE-2026-88779 Crashes SAML-Configured Appliances — Including Boxes Patched Days Earlier — CISA Deadline October 7

NetScaler administrators spent the first week of October patching the same appliances twice. On October 4, Citrix released emergency builds fixing CVE-2026-88779, a high-severity (CVSS 8.7) memory overflow in NetScaler ADC and NetScaler Gateway that the company says has been used in targeted attacks on unmitigated deployments, causing denial of service. The flaw arrives days after CVE-2026-88771 and CVE-2026-88772, the exploited pre-auth RCE zero-days we covered in our September 28 report — and exploitation has been observed even on appliances that had just been patched for those flaws.

The precondition for CVE-2026-88779 is SAML: the appliance must be configured as a SAML service provider (add authentication samlAction) or SAML identity provider (add authentication samlIdPProfile) in conjunction with Gateway or AAA functionality. "If the condition is triggered repeatedly, the service may remain unavailable," Citrix said, adding that its analysis "indicates this issue affects service availability, and we have not identified an impact on the integrity of customer data." Administrators first sounded the alarm on October 2, when fully patched 14.1-73.37 appliances began crash-looping — the nsaaad authentication daemon died repeatedly until the Pitboss process hit its restart limit and rebooted the box. Logs showed crafted authentication usernames containing shell commands that downloaded a payload from 213.209.159[.]55, saved it as /v, and executed it; the administrator stressed the logs showed attempted exploitation and correlated crashes, not confirmed execution.

Fixed builds are 14.1-73.41 and later, 13.1-64.28 and later, 14.1-FIPS 14.1-73.41 FIPS and later, and 13.1-FIPS/NDcPP 13.1-37.282 and later — and Citrix explicitly warns customers who upgraded for CVE-2026-88771 through 88778 to upgrade again. While teams plan the upgrade, Citrix pushed Global Deny List signatures that block known malicious IPs, and its compromise-check script is available via NetScaler Console (watchTowr cautions the latest version can report a false positive about suspicious nobody processes, so review results carefully and preserve evidence before updating). Bishop Fox and watchTowr are credited with the report; watchTowr reproduced the flaw within hours of seeing honeypot activity and told SecurityWeek it is a DoS-only bug whose crashes appear designed to make exploitation of CVE-2026-88771 easier.

The RCE question is not closed: Kevin Beaumont — who dubbed the pair "PitScaler" and this flaw its sequel — reported patched 13.1 and 14.1 honeypots crashing from multiple source IPs, "sprayed and prayed," with one honeypot found running a downloaded malware binary. He notes CVE-2025-6543 was initially described the same way before RCE was confirmed. CISA added CVE-2026-88779 to KEV on October 4 with a October 7 deadline for federal agencies — the sixth exploited NetScaler flaw added to the catalog in 2026.

What Should You Do?

  1. Upgrade every SAML-configured ADC and Gateway now — 14.1-73.41+, 13.1-64.28+, or the FIPS equivalents — including appliances you patched for the September zero-days days ago.
  2. Check your configuration for samlAction or samlIdPProfile entries to know whether you're in scope; no SAML means no exposure to this flaw.
  3. Load Citrix's Global Deny List signatures as interim cover, and run the NetScaler Console compromise-check script before updating — preserving logs and any suspicious files first.
  4. Review authentication logs for crafted usernames — shell metacharacters in SAML username fields, crashes of nsaaad, unexpected reboots. Any confirmed write is full compromise: isolate, rotate credentials, rebuild.

The WAF Angle

A denial-of-service flaw on the authentication path is hard medicine for edge security teams: the crashing request is a structurally valid authentication attempt, so signature-based defenses see "normal" traffic. But the field contents are not normal — usernames carrying shell command strings are exactly the kind of payload anomaly a WAF with request-inspection rules can catch today, even before you can patch: block or flag shell metacharacters and URL-encoded variants in SAML authentication fields, and alert on authentication-daemon restart bursts, which is how this campaign announced itself on Reddit before any vendor advisory existed. The operational lesson is patch-fatigue-awareness: three rounds of emergency NetScaler updates in ten days is precisely the cadence attackers count on, because teams that "finished" patching last week stop watching the same logs. Repeat-verification of the same appliance class isn't duplication — it's the 2026 edge-device reality.

Sources