Citrix NetScaler zero-days stay exploited after emergency patches
Actively exploited Citrix NetScaler flaws CVE-2026-88779 and CVE-2026-88771 drew emergency patches and a CISA deadline of October 7.
Citrix issued emergency updates for CVE-2026-88779, a CVSS 8.7 memory-buffer overflow in customer-managed NetScaler ADC and Gateway appliances that use SAML, described variously as Gateway or AAA configurations or as a SAML service provider or identity provider. Citrix said targeted attacks on unmitigated appliances caused denial of service, including repeated outages, and that it found no impact on data integrity; SecurityWeek, BleepingComputer, and honeypot reporting instead describe possible code execution, webshell attempts, a downloaded malware binary, and activity against already patched honeypots, including a binary Kevin Beaumont observed and a payload from 213.209.159.55. Cited fixes are 14.1-73.41 and 13.1-64.28 plus FIPS builds, while Canada's October 5 advisory AV26-996 also lists ADC releases before 13.1-37.282; Citrix published deny-list signatures and an indicator script and credited Bishop Fox and watchTowr. CISA added the bug to the Known Exploited Vulnerabilities catalog on October 4, 2026, which SecurityWeek called the sixth exploited NetScaler CVE listed in 2026, and told U.S. federal agencies to mitigate by October 7 and perform forensic triage, alongside U.S. and Australian warnings. Separately, CVE-2026-88771, a CVSS 9.5 pre-authentication command-injection flaw patched September 27 in 14.1-73.37 and 13.1-64.23 including FIPS and NDcPP builds, and CVE-2026-88772 remain under active exploitation; October 8 LevelBlue reporting describes reverse shells, a PHP web shell, creation of superuser sec_monitor, and theft of ns.conf, while Mandiant cited likely victims in North America and Europe and Infosecurity noted KEV-listed CVE-2026-8452.
- CVE-2026-88779 is a CVSS 8.7 memory-overflow flaw in customer-managed NetScaler ADC and Gateway using SAML (described as Gateway/AAA or as a SAML SP or IdP); cited fixes are 14.1-73.41 and 13.1-64.28 plus FIPS builds, and Canada's AV26-996…
- Citrix said targeted attacks on unmitigated appliances caused denial of service and that data integrity was unaffected; SecurityWeek, BleepingComputer, and honeypot reports instead describe possible code execution, webshell attempts, a…
- CISA added CVE-2026-88779 to the KEV catalog on October 4, 2026—the sixth exploited NetScaler CVE it listed in 2026, per SecurityWeek—and ordered U.S. federal agencies to mitigate by October 7 and do forensic triage; the U.S. and Australia…
- Citrix published deny-list signatures and an indicator script and credited Bishop Fox and watchTowr; watchTowr said one crafted request can take an appliance offline.
Coverage timelineoldest first · each row is one article
- · 5d agoCitrix NetScaler Keeps Rebooting Following the 0-Day Patch
Cyber Security News· 76
Citrix NetScaler appliances on zero-day fix 14.1-73.37 reboot after crafted SAML traffic crashes nsaaad.
- · 5d agoCitrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update
GBHackers· 76
Patched Citrix NetScaler appliances crash and reboot when malformed SAML requests hit the nsaaad service.
- · 4d agoCitrix patches NetScaler SAML zero-day exploited in attacks
BleepingComputer· 88
Citrix patched actively exploited NetScaler SAML zero-day CVE-2026-88779 after crashes and possible code execution.
Vulnerabilities in this storyAll →
- CVE-2025-65439.211%Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wildpublished · Citrix NetScaler ADC KEV