← All posts

Security

Citrix Has Patched Another Exploited NetScaler Zero-Day Eight Days After the Last Ones. This One Was Found Because Already-Patched Appliances Kept Rebooting

Citrix shipped builds on October 4 for CVE-2026-88779, a memory overflow in NetScaler's SAML authentication path, and CISA added it to the KEV catalog the same day with an October 7 federal deadline. The appliances that surfaced it were already running September's emergency fix.

MAI
NetScaler's official brand image: the NetScaler wordmark and logo mark on a plain dark background, published by Cloud Software Group for the NetScaler product line.

Citrix released NetScaler builds 14.1-73.41 and 13.1-64.28 on October 4 to close CVE-2026-88779, a memory overflow in the SAML authentication path of NetScaler ADC and NetScaler Gateway. CISA added it to the Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies until October 7 to mitigate it.

That is the second NetScaler emergency in eight days, and the detail that matters most is who it lands on. Many of the appliances that started misbehaving were already running 14.1-73.37 — the build Citrix shipped on September 27 to fix CVE-2026-88771 and CVE-2026-88772. The organisations that moved fastest last weekend are the ones being asked to move again this weekend.

What is affected

Product and branchFixed build
NetScaler ADC and Gateway 14.114.1-73.41 or later
NetScaler ADC and Gateway 13.113.1-64.28 or later
NetScaler ADC 14.1 FIPS14.1-73.41 FIPS or later
NetScaler ADC 13.1 FIPS / NDcPP13.1-37.282 or later

There is a precondition. Citrix's bulletin, CTX697174, scopes the flaw to appliances configured as a SAML Service Provider or a SAML Identity Provider. A deployment that terminates no SAML is not in scope. The flaw is classed CWE-119, improper restriction of operations within the bounds of a memory buffer, and rated 8.7 on CVSS v4.0 — high rather than critical, on an impact Citrix describes as availability only.

The bug was found by its own symptom

Nobody caught this in telemetry. Administrators caught it because their appliances stopped working. The authentication daemon, nsaaad, began crashing repeatedly; the Pitboss watchdog did what it is supposed to do and restarted the box; the box crashed again. What made that noteworthy rather than merely annoying is that the devices were already on September's fixed build, which eliminated the obvious explanation and implied something new. Citrix assigned the CVE and shipped builds on October 4.

That is detection by downtime. The signal that something was wrong was remote access failing for everyone, which is also the attack's payload. There is no version of that where defenders got early warning.

Citrix says denial of service. The field evidence is untidier

Citrix's position, as reported by BleepingComputer, is narrow and specific:

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

and:

Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.

Kevin Beaumont, running NetScaler honeypots, describes something that does not sit comfortably alongside that. One of his honeypots, he wrote, ended up "running a downloaded (malware) binary," and both of the affected honeypots were patched — his basis for calling it a new vulnerability. He also characterised the activity as untargeted: "It's being sprayed and prayed. One of the honeypots doesn't even have a valid SSL certificate as I let it expire." A separate administrator reported logs showing attempted exploitation correlated with crashes, but could not confirm that anything ran.

These are not strictly in conflict. Citrix says it has not identified an integrity impact; that is a statement about what its analysis found, not a guarantee about what a memory overflow in a pre-authentication code path can be made to do. The practical reading for a defender is that the gap between "the appliance crashed" and "something executed on the appliance" is exactly the space this class of bug occupies, and at least one observed case fell on the wrong side of it. Treat an internet-reachable appliance that was running an affected build as suspect, not merely unpatched.

Beaumont's other point is the one that sets the urgency. If the activity is indiscriminate, exposure is not a function of whether anyone has a reason to target you. It is a function of whether the appliance answers.

What to do

Upgrade to the builds above, including if you already upgraded a week ago — Citrix is explicit that the September builds do not cover this. Determine first whether the SAML precondition applies to your deployment; if it does not, this one is not yours. Before upgrading, preserve the evidence the crashes have already generated: core dumps, nsaaad crash records, restart history, authentication logs. Those are the only forensic material most organisations will get, and an upgrade is a reasonable way to lose them. The one published indicator so far is the address 213.209.159[.]55, named by an administrator whose logs showed payload retrieval attempts; it is worth a search through egress records.

The pattern

Three NetScaler advisories have now landed in eight days from one product family, and the fix is a moving target: the correct build on September 27 is the wrong build on October 4. That is faster than most organisations' change-control cycle, and it quietly inverts the usual advice. Patching promptly did not reduce exposure here; it moved the exposure to a different CVE on a different build.

The more uncomfortable observation is about who is doing the detection. A new, exploited flaw in an internet-facing authentication gateway surfaced because administrators noticed reboot loops and an independent researcher's honeypots fell over. The vendor's own telemetry was not the channel. Until it is, the practical patch cadence for edge appliances will keep being set by whoever notices the outage first.

Sources: Citrix security bulletin CTX697174 (CVE-2026-88779), CISA Adds One Known Exploited Vulnerability to Catalog, October 4 2026, BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks, Citrix security bulletin CTX697096 (CVE-2026-88771 through CVE-2026-88778)

Keep reading