ConicPlex

Start Your Project

A network appliance with glowing status LEDs next to a laptop and an employee ID badge on a desk, representing NetScaler SAML gateway infrastructure

On this Page

Citrix Patches a NetScaler Zero-Day Exploited to Knock SAML Gateways Offline (CVE-2026-88779)

Citrix patched a new NetScaler zero-day, CVE-2026-88779, already being exploited in targeted attacks. Here is what is affected and what to do.

Sameer Malek

October 5, 2026

Citrix has patched a new NetScaler zero-day, CVE-2026-88779, that attackers were already exploiting before a fix shipped. The flaw is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that crashes appliances configured as a SAML service provider or identity provider, and CISA added it to its Known Exploited Vulnerabilities catalog on October 4, 2026, giving federal agencies until October 7 to patch. It’s Citrix’s second emergency NetScaler bulletin in under two weeks.

What CVE-2026-88779 Actually Does

According to Citrix’s own security bulletin (CTX697174), the bug carries a CVSS 4.0 score of 8.7 and is described plainly as a memory overflow vulnerability leading to denial of service. It only affects appliances where SAML is actually configured, either as a service provider or an identity provider, not the default out-of-the-box setup. That’s narrower than the pair of NetScaler flaws Citrix patched on September 27, where one of the two bugs hit every deployment regardless of configuration.

Narrower doesn’t mean low priority here. The Hacker News reports the flaw was found and exploited in targeted attacks before Citrix had a patch ready, with researchers at Bishop Fox and watchTowr credited in the disclosure. BleepingComputer’s coverage notes that while Citrix classifies it strictly as a crash-inducing DoS bug, some researchers monitoring exploitation activity suspect the memory corruption could potentially be pushed further than a simple denial of service.

Affected and Fixed Versions

  • NetScaler ADC / Gateway 14.1 before 14.1-73.41, fixed in 14.1-73.41 and later
  • NetScaler ADC / Gateway 13.1 before 13.1-64.28, fixed in 13.1-64.28 and later
  • NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS, fixed in 14.1-73.41 FIPS and later
  • NetScaler ADC/Gateway 13.1-FIPS and 13.1-NDcPP before 13.1-37.282, fixed in 13.1-37.282 and later

Who Needs to Act

If you run NetScaler ADC or Gateway as a SAML identity provider or service provider, for SSO into internal apps or as a VPN gateway tied into SAML-based auth, patch now rather than waiting for a maintenance window. CISA’s short federal deadline is a signal of how seriously the agency is treating active exploitation, not just a government-only concern. Worth checking logs for unexpected appliance restarts or crashes around the SAML processing path since the patch shipped, since that’s consistent with exploitation attempts against this bug.

This is the second NetScaler zero-day Citrix has had to rush out a fix for since late September, following the CVE-2026-88771 and CVE-2026-88772 pair patched on September 27. Two emergency bulletins on the same product line inside two weeks is a pattern worth noticing if NetScaler sits anywhere in your infrastructure: whoever owns patching for it should be on a short notification cycle for Citrix advisories right now, not checking in once a quarter.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Platforms

A developer's desk at night with a monitor glowing WordPress blue showing blurred code, a coffee mug, and a notebook with a hand-drawn network diagram of connected nodes representing a community platform

BuddyPress or Custom Build: What a WordPress Community Platform Actually Needs

BuddyPress is still the fastest way to get a basic community layer running on WordPress: activity streams, member profiles, groups,…

Aftab Memon

October 5, 2026

Plugins

Flat illustration of a shopping cart with a dashed threshold line marking a minimum order amount

How to Set a Minimum Order Amount in WooCommerce (4 Plugins Compared)

WooCommerce has no native way to require a minimum cart total before checkout. Here are 4 real plugins that add…

Husen Memon

October 5, 2026

Plugins

Flat illustration of a purple shopping bag with a reserved tag and a clock, representing a WooCommerce pre-order plugin

Best WooCommerce Pre-Order Plugins: 3 Real Options Compared

Three real WooCommerce pre-order plugins compared: Pre-Orders for WooCommerce, YITH Pre-Order, and PRENA, with real prices, requirements, and setup steps…

Sajil Memon

October 5, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant