On October 4, CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog, with a federal remediation due date of October 7 12. The bug is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, CWE-119, scored 8.7 under CVSS v4.0 3. SecurityWeek counts it as the sixth exploited NetScaler vulnerability CISA has added this year 4.

The CVSS metrics describe the shape of the bug. The attack runs over the network, needs no credentials and no user interaction, and the impact it records is availability 3. The first visible effect is an appliance that stops answering.

The precondition decides the scope

The bug reaches NetScaler deployments that run as a SAML service provider or a SAML identity provider 3. Citrix published the check for both: a line that reads add authentication samlAction means the box is a SAML SP, and add authentication samlIdPProfile means it is a SAML IdP 35.

The affected builds are 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, with matching windows on the FIPS and NDcPP trains 3. The fixed builds carry the same numbering or later: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 3.

My first move on a KEV entry like this is to find out which boxes in our environment sit in front of single sign-on with a SAML action in the configuration, and to get that answer from the current config rather than from memory. A NetScaler that does load balancing is a different conversation from one that brokers every SSO login at the edge.

The impact on the login path

SAML at the edge sits between a person and every application behind sign-on, so an outage there spreads past a single application. Citrix says it has observed targeted attacks on unmitigated deployments that lead to denial of service, and that a repeated trigger can keep the service unavailable 5. The same post says the company has not identified an impact on the integrity of customer data 5. The confirmed effect is the availability hit.

SecurityWeek reports signs the bug may also be exploitable for remote code execution, and describes what one researcher saw. Kevin Beaumont reported exploitation attempts against honeypots that were on patched versions, and one of his honeypots was running a downloaded binary 4. Admins quoted in the same piece described authentication requests with shell commands hidden in the username field, along with a caution that nobody proved the fetched script ran 4. I carry the code execution path in the write-up as unresolved. I plan a maintenance window for the denial of service. The code execution path is why I hunt, and I can start the hunt before the window opens.

The relay packet

I assess and relay. The appliance belongs to the team that runs it, and the useful thing I hand over is the order: the precondition, the build, and the reasoning behind both.

The packet has four parts. First, the precondition: run the two config searches on every NetScaler that touches sign-on. Second, the build on each box, read against the fixed versions above. Third, the interim control for anything that cannot move before the due date. Fourth, the date itself, so the owning team can set the pace.

Citrix published Global Deny List signatures that work as virtual patching while a team plans the upgrade 5. The feature needs NetScaler Console with virtual patching turned on, the appliance has to sit in the narrow version window below the fix line, and the signature version needs to be v24 or higher 5. Two commands confirm it: show appfw signatures shows whether a signature set is present, and stat denylist global AAA_REQUEST shows whether the rule is firing 5.

A change record does not prove coverage

NetScaler teams spent the end of September responding to two earlier zero-days, CVE-2026-88771 and CVE-2026-88772 4. A team that upgraded for those needs another upgrade if the SAML precondition holds 5. SecurityWeek notes that admins reported appliances on the latest version rebooting, which is how the new bug surfaced 4.

For that reason the relay asks for the output of a version command on the appliance and treats the change record as supporting evidence. The ticket from an earlier fix proves work happened. Whether the appliance is covered comes down to the version output, and that is the first thing I ask the owning team for.

The deadline, the flag, and the hunt

The KEV entry carries a field that reads “Forensic triage required per BOD 26-04: Yes” 2. BOD 26-04 binds federal civilian agencies, and my employer is not one. The flag matters to a team outside the federal scope too: CISA expects agencies to check whether a system was compromised before the patch went on, and that expectation fits a bug that followed two others in the same product 1.

I fold the triage step into the relay as a hunt. Pull the authentication logs from the exposure window and look for the request patterns admins described, including shell commands in the username field 4. If the logs show crash behavior and nothing else, the upgrade closes the item. If anything matches, the upgrade becomes the first step of an incident response.

CISA set the due date at October 7 when it listed the bug on October 4 2. Three days is short, and the expensive part for the team that owns the appliance is proving the precondition and finding the boxes in a week that has a patching cycle in it.

The precondition is mine to settle from the analyst seat, and the upgrade belongs to the team that owns the box.


  1. CISA. (2026, October 4). CISA adds one known exploited vulnerability to catalog. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog ↩︎ ↩︎

  2. CISA. (n.d.). Known exploited vulnerabilities catalog. Cybersecurity and Infrastructure Security Agency. Retrieved October 5, 2026, from https://www.cisa.gov/known-exploited-vulnerabilities-catalog ↩︎ ↩︎ ↩︎

  3. Citrix. (2026, October 4). Citrix NetScaler ADC and Citrix NetScaler Gateway security bulletin for CVE-2026-88779 (Article CTX697174). Citrix Support. https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  4. Kovacs, E. (n.d.). Exploitation of Citrix NetScaler zero-day hits appliances patched days earlier. SecurityWeek. https://www.securityweek.com/exploitation-of-citrix-netscaler-zero-day-hits-appliances-patched-days-earlier/ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  5. Cloud Software Group. (2026, October 3). Understanding and addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway. Citrix Community. https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎