Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Citrix NetScaler zero-day in SAML setups is third exploited flaw; CISA sets Oct. 7 date

CVE-2026-88779 lets attackers crash NetScaler appliances set up for SAML sign-in, and Rapid7 says attackers are chaining it with an earlier remote code execution bug.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Citrix disclosed CVE-2026-88779 on October 3, a memory overflow in NetScaler ADC and Gateway SAML setups rated 8.7.
  • 2Citrix says targeted attacks can cause denial of service; Rapid7 says attackers are chaining it with remote code execution flaw CVE-2026-88771.
  • 3CISA added the flaw to its exploited list and gave federal agencies until October 7 to patch and run forensic triage.

The news

Citrix disclosed another exploited Citrix NetScaler zero-day on October 3: CVE-2026-88779, a memory overflow in NetScaler ADC and Gateway appliances configured for SAML single sign-on. Citrix said targeted attacks on unpatched devices can cause denial of service, crashing appliances that handle sign-ins for large organizations.

The flaw is rated 8.7 out of 10 on the CVSS v4.0 scale and affects NetScaler ADC and Gateway 14.1 before build 14.1-73.41 and 13.1 before 13.1-64.28, plus FIPS and NDcPP builds, according to Citrix's bulletin. Only appliances set up as a SAML service provider or SAML identity provider are affected; SAML (Security Assertion Markup Language) is a standard that lets one system vouch for a user's identity to another. Citrix said it updates its own managed cloud services and Adaptive Authentication itself.

Customers began reporting unusual exploitation on Friday, October 2, even on appliances with every patch installed, The Record reported. Security researcher Kevin Beaumont said one of his patched honeypots, decoy systems set up to attract attackers, ended up running a downloaded malware binary, according to BleepingComputer, which said researchers are investigating whether the bug allows more than a crash. Citrix said it has not identified an impact on the integrity of customer data, according to The Record.

Researchers tie the new bug to the earlier attacks. Andrew Galvin, a detection and response analyst at Rapid7, said attackers are chaining CVE-2026-88779 with CVE-2026-88771, a remote code execution flaw Citrix disclosed earlier, using a pre-authentication log-poisoning injection and an unrelated SAML-parsing crash, Cybersecurity Dive reported. Benjamin Harris, founder of watchTowr, said the new bug has no technical link to the earlier issues but suspects it was used to crash machines on purpose to speed up exploitation of CVE-2026-88771, The Record reported.

The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on Sunday, October 4, and ordered federal agencies to patch by Wednesday, October 7, and conduct forensic triage. CVE-2026-88771 and CVE-2026-88772, the two flaws disclosed in late September, remain under active exploitation despite patches, according to The Record.

Mandiant has identified organizations hit in the earlier campaign across government, financial services, technology, education and legal and professional services in North America and Europe, The Record reported. Cybersecurity Dive, citing the Shadowserver Foundation, reported more than 20,000 NetScaler instances that are exposed and potentially vulnerable to exploitation.

The numbers

New vulnerability
CVE-2026-88779
Severity score (CVSS v4.0)
8.7
Fixed builds
14.1-73.41 / 13.1-64.28
CISA deadline for federal agencies
October 7, 2026
Exposed NetScaler instances (Shadowserver, per Cybersecurity Dive)
20,000+

Why CEOs should care

If you run NetScaler for remote access or single sign-on, this is another urgent patch cycle on the same appliance. Check whether your devices use the samlAction or samlIdPProfile settings Citrix lists as preconditions, and move to 14.1-73.41 or 13.1-64.28 or later. Because researchers tie the crashes to exploitation of CVE-2026-88771, patching alone is not enough: hunt for signs of compromise from the earlier flaws and treat unexplained appliance crashes as possible evidence.

CIOs should plan for disruption. A denial-of-service bug on an authentication gateway can take down sign-in for employees and customers, so schedule the update quickly, confirm a fallback login path and tell business units what an outage would affect.

Boards and CFOs should treat three exploited flaws in one product in quick succession as a vendor-risk question. Ask how much of your remote access and sign-on depends on a single edge appliance, how fast your team can patch it and whether you have incident response help on call. CISA's order to run forensic triage signals that installing the update may not close the exposure on its own.

The bigger picture

Edge appliances that sit on the internet and handle sign-ins are high-value targets, because a flaw that works before login can give attackers a foothold in the network. NetScaler has been hit by three exploited bugs in quick succession, and attackers appear to be combining them, according to Rapid7 and watchTowr.

BleepingComputer pointed to a precedent: CVE-2025-6543, an earlier NetScaler bug first described as denial of service, was later shown in attacks to allow remote code execution. That history is why researchers are testing whether CVE-2026-88779 can do more than crash a device.

What’s next

Watch for whether researchers confirm code execution through CVE-2026-88779, any update to Citrix's bulletin or CISA's KEV entry, and new guidance on hunting for compromise tied to CVE-2026-88771. Federal agencies face the October 7 deadline; private companies can treat it as a benchmark for their own patching.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CitrixNetScalerCISAZero-dayRapid7

Earlier coverage of Citrix

All Citrix coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.