Last week’s NetScaler upgrade does not count. Citrix shipped another emergency build Sunday for a SAML memory bug that is already being used in attacks, and CISA’s federal due date is Wednesday, October 7. If the appliance is a SAML login for your VPN or apps, this is the Monday item.
Last week’s NetScaler upgrade does not count.
What happened
Citrix published CTX697174 on October 3 (Pacific) for CVE-2026-88779, a memory-buffer flaw in customer-managed NetScaler ADC and NetScaler Gateway. The precondition is narrow and common: the box is configured as a SAML service provider (add authentication samlAction) or as a SAML identity provider (add authentication samlIdPProfile). No login is required to hit the path. Citrix rates it high (CVSS v4.0 8.7) and describes the impact as denial of service: repeated triggers can keep the service down. Cloud-managed NetScaler and Citrix-managed Adaptive Authentication are updated by Citrix; this bulletin is for appliances you run.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
That is not the whole weekend. Administrators on builds that already fixed last month’s pair (CVE-2026-88771 through CVE-2026-88778), including 14.1-73.37, reported nsaaad crash loops and Pitboss reboots. One admin saw authentication usernames carrying shell commands that tried to download a file, immediately before confirmed crash sequences, and said the logs showed an attempt, not proof the commands ran. Kevin Beaumont reported patched honeypots crashing from multiple source addresses and, on one of them, a downloaded binary running. watchTowr said it reproduced the issue. Citrix’s position, in the bulletin and a related post, is availability impact, and that it has not identified an integrity impact on customer data. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4 and set the federal due date at October 7, with forensic triage required under BOD 26-04.
Citrix is explicit that customers who already installed the builds from the earlier bulletin, and who meet the SAML precondition, need to upgrade again. Fixed releases: 14.1-73.41 and later, 13.1-64.28 and later on the 13.1 line, 14.1-73.41 FIPS and later, and 13.1-37.282 and later for 13.1-FIPS and 13.1-NDcPP. Secure Private Access hybrid deployments that use NetScaler instances are in scope too.
Why it matters
This is the remote-access edge. A gateway that reboots on a timer is an outage. A gateway that researchers are watching for code execution is an incident until you prove otherwise. Teams that closed last week’s NetScaler ticket will miss this one if the change record says “patched.”
Citrix and the researchers are not telling the same story yet. Plan for the vendor’s denial-of-service fix, and hunt as if a crash loop might be more than a crash. Do not wait for a CVSS rewrite.
What to do first
- On every customer-managed NetScaler, run the config check:
add authentication samlActionoradd authentication samlIdPProfile. If neither is present, this CVE’s precondition is not met. Record that and move on. - If either is present, schedule 14.1-73.41 (or 13.1-64.28, or the matching FIPS/NDcPP build) before Wednesday. A build that fixed CVE-2026-88771 through CVE-2026-88778 is not this fix.
- Before you upgrade a box that has been crash-looping, preserve logs. Updates can wipe the forensic view CISA is asking federal agencies to check.
- Hunt for repeated
nsaaadcrashes, Pitboss restart limits, unexpected reboots since Thursday, and authentication attempts whose usernames contain shell syntax or download commands. - Citrix is also offering Global Deny Lists for known malicious addresses. Treat that as a speed bump. The bulletin’s required action is the new build.
- After the upgrade, confirm the running version, not the ticket. Then re-check that SAML login still works for a real user.
Forward this
If you own the VPN or the SAML gateway: the NetScaler build from late September is not the Sunday build. Upgrade customer-managed appliances that use SAML to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS or 13.1-37.282) before Wednesday, and do not treat a reboot loop as “just noisy.”
Details
- CVE: CVE-2026-88779 — CWE-119 memory overflow, denial of service per Citrix (CVSS v4.0 8.7: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Precondition: NetScaler ADC or Gateway configured as SAML SP or SAML IdP
- Affected: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; 14.1-FIPS before 14.1-73.41 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.282
- Fixed: 14.1-73.41+, 13.1-64.28+, 14.1-73.41 FIPS+, 13.1-37.282+
- Scope: Customer-managed appliances, including Secure Private Access hybrid NetScaler instances. Not Citrix-managed cloud.
- KEV: Added 2026-10-04. Federal due date 2026-10-07. Forensic triage required under BOD 26-04.
- Different from: CVE-2026-88771 and CVE-2026-88772 (late September). Those builds do not close this one.
Hunt / verify
- Show version and compare to the fixed build for that train.
- Grep the running config for
samlActionandsamlIdPProfile. - Review
nsaaad/ Pitboss crash and reboot history since 2026-10-01, plus AAA/SAML authentication logs for odd usernames. - If you find a downloaded binary or unexpected process, handle it as a compromise, not a failed scan.
Slack paste: NetScaler SAML boxes need 14.1-73.41 or 13.1-64.28 (FIPS equivalents too) before Wed Oct 7 — last week’s build does not count. Hunt nsaaad/Pitboss crash loops before you upgrade. CVE-2026-88779, KEV due 2026-10-07.
Sources
- https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html
- https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
- https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.