1. Home
  2. Resources
  3. News
  4. Citrix NetScaler SAML Zero-Day (CVE-2026-88779):…

Citrix NetScaler SAML Zero-Day (CVE-2026-88779): Patch, Then Hunt

TL;DR: CVE-2026-88779 is a memory overflow in Citrix NetScaler ADC and Gateway that attackers are exploiting now, and any on-premises appliance configured for SAML authentication should be patched and checked for compromise today. INVITE treats a KEV-listed edge flaw as a two-part job, patch first and then hunt, because a fix does not remove a webshell that is already in place. This briefing is for CISOs, IT Directors, and VPs of IT at mid-market and enterprise organizations that run NetScaler for remote access or application delivery.

What is the NetScaler SAML zero-day, CVE-2026-88779?

CVE-2026-88779 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that is being exploited in the wild. It affects only on-premises deployments configured for SAML authentication, as either a service provider or an identity provider, together with Gateway or AAA functionality. CISA added it to the Known Exploited Vulnerabilities catalog on October 4, with a federal remediation deadline of October 7.

Observed attacks crash the appliance and can keep the service down when the flaw is triggered repeatedly. Researchers also report attempts to download and run a script that installs webshells. Whether the flaw leads to full remote code execution is still unconfirmed, so plan as if it can.

Which NetScaler versions are affected, and what are the fixed releases?

NetScaler ADC and Gateway 14.1 builds before 14.1-73.41 and 13.1 builds before 13.1-64.28 are affected. FIPS and NDcPP builds have their own fixed releases: 14.1-73.41 FIPS and 13.1-37.282 FIPS/NDcPP.

Product lineVulnerable beforeMove to
ADC and Gateway 14.114.1-73.4114.1-73.41 or later
ADC and Gateway 13.113.1-64.2813.1-64.28 or later
ADC FIPS 14.114.1-73.41 FIPS14.1-73.41 FIPS or later
ADC FIPS and NDcPP 13.113.1-37.28213.1-37.282 FIPS/NDcPP or later

How do you patch a NetScaler appliance and check for compromise?

Patch and hunt in the same change window, in this order:

  1. Confirm exposure. Identify every NetScaler with a SAML profile bound to a Gateway or AAA virtual server, including appliances nobody has touched in a while.
  2. Preserve evidence before upgrading. Capture logs and a configuration backup first. Reports show reboots and crashes after patching, and an upgrade can erase traces.
  3. Block known bad sources. While you schedule the upgrade, apply Citrix’s published signatures through the Global Deny List feature.
  4. Upgrade to a fixed release. Treat this as an emergency change, not a monthly patch cycle.
  5. Run Citrix’s indicator-of-compromise script through NetScaler Console and review results by hand. It can flag unusual “nobody” processes that turn out to be benign.
  6. Look for webshells and unexpected scripts. Review the file system and outbound connections from the appliance, then rotate credentials and secrets that the device handled.

Why do edge appliance flaws keep repeating?

Internet-facing gateways hold the keys to remote access, so attackers keep returning to them. This is the same pattern as the Cisco Catalyst SD-WAN flaw INVITE covered on October 1. The Cisco SD-WAN zero-day post walks through the same patch-then-hunt discipline.

The measurable outcomes to track are time to patch an exploited edge flaw, dwell time before a compromise is found, and the percentage of edge devices with continuous log coverage. INVITE’s managed detection and response and cybersecurity services give IT teams in Salt Lake City and Phoenix a 24×7 team watching those signals when internal staff are off shift.

Frequently Asked Questions

Is every NetScaler appliance vulnerable to CVE-2026-88779?
No. The flaw affects on-premises NetScaler ADC and Gateway configured for SAML authentication with Gateway or AAA. Other configurations are not described as affected, but confirm by reviewing your own bindings.

Is patching enough?
No. Active exploitation began before fixes shipped, and attackers have attempted to install webshells. After patching, run Citrix’s indicator-of-compromise script and review the appliance for persistence.

What if we cannot patch today?
Apply Citrix’s Global Deny List signatures to block known malicious sources, restrict exposure where you can, and schedule the upgrade as an emergency change.

Does this affect NetScaler in the cloud?
Advisory coverage describes on-premises deployments. Confirm scope against Citrix’s current bulletin for your deployment model.

Who can help check our environment?
INVITE security engineers can review exposure and run a compromise assessment. Schedule a 30-minute architecture review with an INVITE security engineer.