Citrix released emergency updates for CVE-2026-88779, an actively exploited memory-buffer bounds vulnerability affecting NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication with Gateway or AAA functionality. The flaw has a reported CVSS score of 8.7 and can cause denial of service through repeated process crashes and appliance reboots. Administrators observed shell commands embedded in authentication usernames, while researcher Kevin Beaumont reported a downloaded malware binary running on a patched honeypot; remote code execution through this specific vulnerability remains under investigation.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 4, setting an October 7, 2026 remediation deadline for Federal Civilian Executive Branch agencies. The catalog entry requires forensic triage and vendor mitigations in accordance with BOD 26-04; use in ransomware campaigns is unknown. Citrix urges administrators to install the applicable fixed releases immediately, including on appliances already updated for previously disclosed vulnerabilities.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-88779 to the KEV catalog, identifying it as known to be exploited and requiring forensic triage and vendor-directed mitigations under BOD 26-04. The entry set an October 7, 2026 remediation deadline for federal civilian agencies and listed ransomware campaign use as unknown.
Citrix released NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28 early Sunday to address an actively exploited memory-buffer vulnerability affecting SAML deployments with Gateway or AAA functionality. Citrix reported denial-of-service attacks, provided applicable FIPS upgrade guidance and Global Deny Lists, and urged affected customers to upgrade even if they had installed earlier security updates.
Citrix published a security notice describing a newly observed SAML authentication issue in customer-managed NetScaler deployments and advised affected customers to contact support. Citrix confirmed that the issue differed from previously disclosed NetScaler vulnerabilities.
Administrators first reported attack activity after recently patched NetScaler appliances began rebooting unexpectedly. Reports included repeated nsaaad crashes that exhausted the Pitboss process restart limit and forced appliance reboots.
Norway's NSM acknowledged Citrix's clarification that CVE-2026-88779 causes denial of service after initially citing reports of unauthenticated arbitrary code execution. NSM retained a very high remediation priority.
watchTowr Labs reported reproducing CVE-2026-88779 after investigating NetScaler honeypot activity. The researchers had not disclosed technical reproduction details.
Beaumont subsequently reported that one previously patched honeypot was running a downloaded malware binary, raising concerns about exploitation beyond denial of service. Remote code execution through CVE-2026-88779 remained under investigation and was not established by Citrix's assessment.
Kevin Beaumont reported that NetScaler 13.1 and 14.1 honeypots with previously available patches crashed after receiving requests from multiple source IP addresses. He characterized the activity as broad spraying, including against a honeypot with an expired SSL certificate.
An administrator investigating NetScaler 14.1-73.37 found crafted authentication usernames containing commands intended to download and execute a payload from 213.209.159[.]55. The requests preceded three confirmed crash sequences, but the logs did not establish successful command execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.