Citrix NetScaler customers reported repeated reboots after installing build 14.1-73.37, the emergency update for actively exploited vulnerabilities CVE-2026-88771 and CVE-2026-88772, known as “Pitscaler.” Crafted SAML authentication traffic reportedly crashes the nsaaad service and can trigger watchdog-driven restarts, creating a potential denial-of-service condition. Subsequent reporting described an apparent new zero-day exploit circulating on October 2: researcher Kevin Beaumont reported a downloaded malware binary running on a patched honeypot and suggested a possible bypass of the earlier fixes. watchTowr Labs said it reproduced the vulnerability, reportedly affecting the latest NetScaler version and involving large volumes of SAML requests. The reboot reports alone do not establish compromise or a patch bypass.
Citrix acknowledged a newly observed SAML issue and said engineering and support teams were investigating and preparing a security bulletin and fixed build. No new CVE, final fixed-build number, or effective countermeasure was reported as available at publication. Administrators should preserve crash logs and forensic evidence, correlate failures with authentication traffic, verify patch levels across all appliance nodes, and monitor Citrix advisories for mitigation and release guidance. Investigations should distinguish service crashes from evidence of code execution and check for persistence from compromises predating the emergency update.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
An exploit for an apparent new NetScaler vulnerability reportedly began circulating on the evening of October 2, 2026. The vulnerability was reported to affect the latest operating-system version and to be triggerable through large volumes of SAML requests.
Citrix characterized the SAML-related reboot behavior as configuration-dependent and distinct from CVE-2026-88771 and CVE-2026-88772, stating that it does not indicate a bypass of the existing fixes. It advised customers to retain the security patches and review affected Gateway and AAA SAML configurations while a corrected build remained pending.
Citrix acknowledged the issue, said its engineering and support teams were investigating, and advised affected customers to contact support and review temporary SAML deployment guidance. It said a security bulletin and fixed build were being prepared, but the reported notice supplied no new CVE identifier or final fixed-release number.
watchTowr Labs stated that its team had successfully reproduced the apparent new NetScaler vulnerability.
Security researcher Kevin Beaumont reported that a downloaded malware binary was running on one of his NetScaler honeypots and said both honeypots had been patched. He suggested that the apparent new vulnerability could bypass the Pitscaler fixes, a claim not established by the separate reboot reports.
Administrators reported repeated nsaaad authentication-service crashes and watchdog-driven appliance restarts after installing the emergency update, with one report involving several customers and severity-one support cases. The failures appeared associated with crafted SAML authentication traffic, but the reboot reports alone did not establish compromise or a bypass of the earlier fixes.
Citrix released NetScaler build 14.1-73.37 as an emergency update for CVE-2026-88771 and CVE-2026-88772. Bulletin CTX697096 also listed build 13.1-64.23 and corresponding FIPS or NDcPP releases as fixes.
Citrix confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 against unpatched systems. Earlier reporting described root access, hidden web shells, and internal tunneling associated with the exploitation campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
decipher.sc
Open sourceheise.de
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.