Citrix NetScaler Hit Again as Exploited SAML Memory Flaw Forces Second Patch Round
Our advisory VTA-2026-000389, published on 2026-09-28, covered the actively exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772. The incident has now moved on. Citrix has disclosed a further high-severity flaw in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88779, and says it has observed targeted attacks against unmitigated deployments. The new issue is a memory-overflow condition that results in denial of service on affected appliances, rated 8.7 under CVSS 4.0. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on 2026-10-04 with a remediation deadline of 7 October for US federal agencies, which places it alongside the two earlier NetScaler entries listed on 2026-09-27.
CVE-2026-88779 does not affect every NetScaler estate. The vulnerable code path is only reachable where the appliance is configured for SAML authentication, acting either as a SAML service provider or as an identity provider, with that SAML functionality used in combination with Gateway or AAA virtual servers. Citrix points administrators to the presence of "add authentication samlAction" and "add authentication samlIdPProfile" entries as the marker for whether the precondition is met. Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with 14.1 FIPS before 14.1-73.41 FIPS and 13.1 FIPS/NDcPP before 13.1-37.282; Secure Private Access Hybrid deployments that sit on NetScaler instances are in scope as well. Citrix has not attributed the activity to any named threat actor and has not published technical detail on how the flaw is being triggered, beyond stating that attackers can repeatedly invoke the condition and leave the service unavailable. The vendor's own analysis indicates the impact is confined to availability, with no identified effect on the integrity of customer data.
The operational problem for defenders is the overlap with the previous emergency cycle. Last week's release covered eight NetScaler vulnerabilities and moved customers onto 14.1-73.37 and 13.1-64.23, and those builds do not carry the fix for CVE-2026-88779 — Citrix's guidance is that appliances already on them remain exposed where the SAML preconditions apply. A temporary reduction in exposure exists for versions 14.1-73.37 through 73.40 and 13.1-64.23 through 64.27 in the form of Global Deny List signatures, available only where the relevant virtual-patching functionality is enabled and verifiable with the "show appfw signatures" command. That leaves many organisations facing a second change window within a single week on the same internet-facing device, which is precisely the kind of patch fatigue attackers count on. Exploitation of CVE-2026-88779 is confirmed in the wild by its KEV listing, although FIRST currently estimates only a 0.5% probability of exploitation activity in the next 30 days, compared with 1.1% for CVE-2026-88771 and 1.3% for CVE-2026-88772.
Strategically, this is another data point in the sustained targeting of edge appliances as an entry route into enterprise networks, and the fact that a third exploited NetScaler CVE surfaced within days of the first two suggests continued research pressure on the same codebase. A denial-of-service flaw reads as less alarming than the remote-access bugs disclosed last week, but NetScaler Gateway is often the sole termination point for VPN and remote workforce access, so repeatedly knocking it offline can halt staff access, break federated logins and disrupt partner integrations without any data ever leaving the environment. For regulated sectors in Malaysia and the wider region, an availability outage on an authentication gateway carries its own reporting and service-level consequences. The exposure is narrowed by the SAML precondition, but SAML-backed single sign-on is common in exactly the large enterprise and public sector estates that attackers prefer, and the 7 October KEV deadline signals how quickly authorities expect the risk to be closed out.
Attack Surface
Remote Access Service, Infrastructure
Tactics
Initial Access, Impact
Techniques
- T1190 – Exploit Public-Facing Application
- T1499 – Endpoint Denial of Service
- T1499.004 – Application or System Exploitation
- T1595 – Active Scanning
SuperPRO's Threat Countermeasures Procedures
- Upgrade customer-managed NetScaler ADC and Gateway to 14.1-73.41 or 13.1-64.28, and FIPS/NDcPP builds to 14.1-73.41 FIPS or 13.1-37.282, per Citrix advisory CTX697174 for CVE-2026-88779. Builds 14.1-73.37 and 13.1-64.23 shipped for last week's zero-days do not contain this fix.
- Run a configuration audit for the strings "add authentication samlAction" and "add authentication samlIdPProfile" on every NetScaler instance to identify appliances that meet the SAML service provider or identity provider precondition and are therefore exploitable.
- Where the upgrade cannot be scheduled immediately on 14.1-73.37 through 73.40 or 13.1-64.23 through 64.27, enable the Global Deny List virtual-patching signatures and confirm their presence by executing "show appfw signatures" on the appliance; treat this strictly as interim cover until the fixed build is installed.
- Include Secure Private Access Hybrid deployments backed by NetScaler instances in the upgrade scope, as Citrix states these are affected by CVE-2026-88779 and require the same fixed builds.
- Alert on repeated NetScaler packet engine restarts, nsppe crash entries in /var/core and ns.log, and sudden drops in Gateway or AAA virtual server availability, since the vendor states attackers can repeatedly trigger the memory-overflow condition to keep the service down.
- Restrict reachability of Gateway and AAA virtual servers that terminate SAML flows to required source ranges at the upstream firewall where business allows, and rate-limit unauthenticated requests to the SAML assertion consumer and IdP endpoints on TCP/443.
- Confirm that CVE-2026-88771 and CVE-2026-88772 from the earlier 14.1-73.37 and 13.1-64.23 release have been fully remediated across the estate, as both remain on the CISA KEV catalog from 2026-09-27 with confirmed in-the-wild exploitation.