Your NetScaler gateway needs another build before Wednesday

By George Bailey   Published: 10/05/26   5 min read

Last week’s NetScaler upgrade does not count. Citrix shipped another emergency build Sunday for a SAML memory bug that is already being used in attacks, and CISA’s federal due date is Wednesday, October 7. If the appliance is a SAML login for your VPN or apps, this is the Monday item.

Last week’s NetScaler upgrade does not count.

What happened

Citrix published CTX697174 on October 3 (Pacific) for CVE-2026-88779, a memory-buffer flaw in customer-managed NetScaler ADC and NetScaler Gateway. The precondition is narrow and common: the box is configured as a SAML service provider (add authentication samlAction) or as a SAML identity provider (add authentication samlIdPProfile). No login is required to hit the path. Citrix rates it high (CVSS v4.0 8.7) and describes the impact as denial of service: repeated triggers can keep the service down. Cloud-managed NetScaler and Citrix-managed Adaptive Authentication are updated by Citrix; this bulletin is for appliances you run.

That is not the whole weekend. Administrators on builds that already fixed last month’s pair (CVE-2026-88771 through CVE-2026-88778), including 14.1-73.37, reported nsaaad crash loops and Pitboss reboots. One admin saw authentication usernames carrying shell commands that tried to download a file, immediately before confirmed crash sequences, and said the logs showed an attempt, not proof the commands ran. Kevin Beaumont reported patched honeypots crashing from multiple source addresses and, on one of them, a downloaded binary running. watchTowr said it reproduced the issue. Citrix’s position, in the bulletin and a related post, is availability impact, and that it has not identified an integrity impact on customer data. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4 and set the federal due date at October 7, with forensic triage required under BOD 26-04.

Citrix is explicit that customers who already installed the builds from the earlier bulletin, and who meet the SAML precondition, need to upgrade again. Fixed releases: 14.1-73.41 and later, 13.1-64.28 and later on the 13.1 line, 14.1-73.41 FIPS and later, and 13.1-37.282 and later for 13.1-FIPS and 13.1-NDcPP. Secure Private Access hybrid deployments that use NetScaler instances are in scope too.

Why it matters

This is the remote-access edge. A gateway that reboots on a timer is an outage. A gateway that researchers are watching for code execution is an incident until you prove otherwise. Teams that closed last week’s NetScaler ticket will miss this one if the change record says “patched.”

Citrix and the researchers are not telling the same story yet. Plan for the vendor’s denial-of-service fix, and hunt as if a crash loop might be more than a crash. Do not wait for a CVSS rewrite.

What to do first

Forward this

If you own the VPN or the SAML gateway: the NetScaler build from late September is not the Sunday build. Upgrade customer-managed appliances that use SAML to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS or 13.1-37.282) before Wednesday, and do not treat a reboot loop as “just noisy.”

Details

Hunt / verify

Slack paste: NetScaler SAML boxes need 14.1-73.41 or 13.1-64.28 (FIPS equivalents too) before Wed Oct 7 — last week’s build does not count. Hunt nsaaad/Pitboss crash loops before you upgrade. CVE-2026-88779, KEV due 2026-10-07.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.