Citrix ships emergency NetScaler fix as new SAML zero-day hits patched appliances
Citrix has patched CVE-2026-88779, a NetScaler flaw exploited days after admins updated for two earlier zero-days. Researchers suspect code execution.
Citrix has released emergency updates for NetScaler ADC and NetScaler Gateway after attackers began exploiting a previously unknown flaw in appliances that had been patched only days earlier.
The vulnerability, CVE-2026-88779, is a memory overflow issue with a CVSS score of 8.7. It affects appliances configured as a SAML service provider or SAML identity provider, according to reports from SecurityWeek and BleepingComputer. Citrix said in a blog post that it had seen targeted attacks on unmitigated deployments that can cause denial of service, and that it had found no impact on the integrity of customer data.
Fixes arrived early on Sunday in versions 14.1-73.41 and 13.1-64.28, BleepingComputer reports, with separate builds for FIPS and NDcPP customers. Citrix is also offering deny lists that block known malicious IP addresses but advises installing the updates as soon as possible. Customers who upgraded recently to address CVE-2026-88771 and CVE-2026-88772, two flaws already under attack, need to upgrade again if SAML authentication is configured.
Questions over code execution
Citrix classifies the bug as a denial-of-service issue, but administrators and researchers have reported signs that it may go further. Admins first noticed fully patched appliances rebooting repeatedly. SecurityWeek reports that logs showed authentication requests with shell commands placed in the username field, intended to download and run a script. Researcher Kevin Beaumont, who named the flaw PitScaler 2, said he saw exploitation attempts against patched honeypots and that one of them was running a downloaded malware binary.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 4 and told federal agencies to address it by October 7. SecurityWeek notes it is the sixth exploited NetScaler flaw added to the catalog in 2026.