Citrix Patches New NetScaler Zero-Day Under Active Attack

Citrix Patches Actively Exploited NetScaler Zero-Day (CVE-2026-88779)

CRITICAL
October 6, 2026
October 9, 2026
5m read
VulnerabilityCyberattackPatch Management

Related Entities(initial)

CVE Identifiers

CVE-2026-88779
HIGH
CVSS:8.7

Full Report(when first published)

Executive Summary

On October 5, 2026, Citrix released emergency security updates for a new high-severity zero-day vulnerability, CVE-2026-88779, impacting its NetScaler ADC and NetScaler Gateway products. The vulnerability is a memory overflow issue actively exploited in the wild to cause a denial-of-service (DoS) condition. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog due to confirmed targeted attacks. While the immediate confirmed impact is service disruption, the potential for remote code execution (RCE) is under investigation by security researchers, elevating the urgency for organizations to apply the provided patches.


Vulnerability Details

The vulnerability, tracked as CVE-2026-88779, has a CVSS score of 8.7 and is described as a memory overflow flaw. It affects customer-managed NetScaler appliances that are configured as either a Security Assertion Markup Language (SAML) Service Provider (SP) or a SAML Identity Provider (IdP). An unauthenticated, remote attacker can send a specially crafted request to a vulnerable appliance, triggering the memory overflow condition. This leads to the appliance's packet engine crashing, resulting in a denial-of-service. According to Citrix, repeated exploitation can cause the service to become persistently unavailable, requiring a system reboot to restore functionality.

The flaw's discovery followed reports from system administrators who observed their fully patched appliances (which had just received updates for CVE-2026-88771 and CVE-2026-88772) crashing and rebooting unexpectedly.

Affected Systems

The vulnerability impacts the following customer-managed Citrix products when configured as a SAML SP or IdP:

  • NetScaler ADC
  • NetScaler Gateway

Citrix has released the following updated versions to address the vulnerability:

  • NetScaler ADC and NetScaler Gateway 14.1-12.35 and later
  • NetScaler ADC and NetScaler Gateway 13.1-51.15 and later
  • NetScaler ADC and NetScaler Gateway 13.0-92.21 and later
  • NetScaler ADC 12.1-FIPS 12.1-55.302 and later
  • NetScaler ADC 12.1-NDcPP 12.1-55.302 and later

Cloud services and Citrix-managed appliances are not affected.

Exploitation Status

CVE-2026-88779 is under active, targeted exploitation. Citrix has confirmed observing attacks against unmitigated appliances in the wild. Following these reports, CISA added the vulnerability to its KEV catalog on October 4, 2026, with a remediation deadline of October 7, 2026, for Federal Civilian Executive Branch (FCEB) agencies.

Security researchers, including Kevin Beaumont, have confirmed seeing exploitation attempts against their honeypots. One researcher reported that a honeypot was compromised and downloaded a malware binary, suggesting that the memory corruption could potentially be leveraged for RCE, although this is not yet officially confirmed by Citrix. The security firm WatchTowr successfully reproduced the DoS attack.

Impact Assessment

The primary and confirmed impact of this vulnerability is a denial-of-service (DoS). Successful exploitation can render critical network access and load-balancing services unavailable, disrupting business operations that rely on NetScaler for authentication and application delivery. For organizations using NetScaler as a gateway for remote access, this could mean a complete loss of connectivity for remote workers. The unconfirmed but potential risk of remote code execution (RCE) would represent a far more severe threat, potentially allowing an attacker to gain full control over the appliance, pivot into the internal network, and access sensitive data.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to identify potential exploitation or vulnerable systems:

Type
Log Source
Value
/var/log/ns.log
Description
Check for entries related to packet engine crashes or unexpected reboots.
Type
Network Traffic Pattern
Value
Anomalous SAML requests
Description
Monitor for malformed or unusually large SAML authentication requests directed at the NetScaler appliance.
Type
System Behavior
Value
Unexplained reboots
Description
Correlate unexpected system reboots with inbound traffic logs to identify potential triggers.
Type
Process Name
Value
nsppe
Description
Monitor for crashes or restarts of the NetScaler packet processing engine process.

Detection & Response

  1. Log Analysis: Monitor NetScaler system logs (/var/log/ns.log) for crash reports, memory allocation errors, or messages indicating the packet engine has stopped and restarted. Correlate these events with inbound web traffic logs to identify suspicious source IPs or request patterns targeting SAML endpoints.
  2. Network Monitoring: Deploy network security monitoring to inspect traffic to and from NetScaler appliances. Create alerts for unusually large or malformed SAML packets. Since the exploit causes a crash, a surge in reset connections or timeouts following requests to SAML-configured virtual servers could indicate an attack.
  3. Endpoint Detection and Response (EDR): While the attack targets the appliance, if RCE is achieved, EDR on downstream systems may detect subsequent lateral movement activities originating from the NetScaler's network interfaces.

Mitigation

  1. Immediate Patching: The primary mitigation is to apply the security updates provided by Citrix immediately. This is the only way to fully remediate the vulnerability.
  2. Restrict Access: If patching is not immediately possible, restrict access to the SAML IdP or SP virtual servers to trusted IP addresses only. This is a temporary compensating control and does not replace patching.
  3. Disable SAML: As a last resort, if the appliance cannot be patched, consider temporarily disabling SAML functionality if it is not business-critical. This will likely cause service disruption but will mitigate the immediate threat vector.

Timeline of Events

1
October 3, 2026
Administrators begin reporting crashes on NetScaler appliances that were recently patched for CVE-2026-88771 and CVE-2026-88772.
2
October 4, 2026
CISA adds CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog.
3
October 5, 2026
Citrix confirms the new zero-day vulnerability (CVE-2026-88779) and releases emergency patches.
4
October 6, 2026
This article was published

Article Updates

October 9, 2026

New exploitation attempts for CVE-2026-88779 observed with shellcode, elevating RCE potential. Updated patch versions released by Citrix.

MITRE ATT&CK Mitigations

Applying the vendor-supplied patches is the most critical step to eliminate the vulnerability.

Mapped D3FEND Techniques:

Using an IPS to monitor for and block known exploit signatures can help protect unpatched systems.

Mapped D3FEND Techniques:

Restricting access to the vulnerable SAML endpoints from untrusted networks can reduce the attack surface.

Mapped D3FEND Techniques:

Timeline of Events

1
October 3, 2026

Administrators begin reporting crashes on NetScaler appliances that were recently patched for CVE-2026-88771 and CVE-2026-88772.

2
October 4, 2026

CISA adds CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog.

3
October 5, 2026

Citrix confirms the new zero-day vulnerability (CVE-2026-88779) and releases emergency patches.

Sources & References(when first published)

New NetScaler Zero-Day Exploited in the Wild – CISA Warns to Patch Now
The Hacker News (thehackernews.com) •October 5, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

zero-daydenial-of-serviceSAMLKEVmemory overflow

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.