Citrix NetScaler Gets Another Exploited Zero-Day, and Last Week's Patches Do Not Cover It (CVE-2026-88779)
Scope: Citrix NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality, including devices already updated for CVE-2026-88771 through CVE-2026-88778
Severity: Red
Citrix released emergency updates on October 4, 2026 for CVE-2026-88779 (CVSS 8.7), a memory buffer flaw that has been used in targeted attacks against unmitigated NetScaler deployments. Citrix describes it as a denial-of-service issue and says it has not identified any impact on the integrity of customer data, but researchers are not so sure. Administrators first reported patched appliances rebooting repeatedly on Friday, one administrator saw crafted authentication usernames containing shell commands that tried to download and run a payload from 213.209.159[.]55, and security researcher Kevin Beaumont found a patched honeypot running a downloaded binary. watchTowr Labs has since reproduced the flaw. The attempts so far look like broad spraying rather than targeted intrusion, and successful code execution has not been confirmed in every case. CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 4 with a federal deadline of October 7. Organisations that upgraded recently for the earlier NetScaler flaws must upgrade again. To check exposure, look in the configuration for an "add authentication samlAction" or "add authentication samlIdPProfile" entry. Upgrade to NetScaler 14.1-73.41 or 13.1-64.28 (14.1-73.41 FIPS for FIPS deployments, and 13.1-37.282 for ADC FIPS and NDcPP on the 13.1 branch), apply Citrix's Global Deny Lists for known malicious IP addresses in the meantime, and review appliances for repeated reboots, nsaaad crashes, and unexpected files.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.