P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

CISA lists a third exploited NetScaler flaw seven days after two others, and Citrix calls it denial of service

CISA put CVE-2026-88779 on its exploited list on 4 October with a 7 October deadline. Citrix's bulletin calls it denial of service and does not mention exploitation; a blog says attacks have been observed, and no source says who, how many or since when.

By Parminder Kumar Sharma · · 17 min read

A racked network appliance in a dark equipment room, with an engineer's laptop on a case in front of it showing a status board of blank tiles, one drawn as a hollow amber outline to suggest a service that has dropped out.

Seven days after two, a third

CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue on Sunday 4 October 2026. That is seven days after it added CVE-2026-88771 and CVE-2026-88772, also on a Sunday, and it makes five NetScaler flaws on the list in 39 days, counting from 26 August (our count from the catalogue). The new due date is 7 October, three days from listing. The one word Citrix puts on the flaw is in its own title, "Memory overflow vulnerability leading to Denial of Service", and its CVSS 4.0 vector rates the impact on confidentiality and integrity as none and on availability as high. That scores 8.7, against 9.5 for each of the two flaws listed a week earlier.

What that does not establish. It does not say who is exploiting the flaw, how many appliances are affected, since when, or how the attacks were found. It does not say that denial of service is all the exploitation has done: it is the consequence Citrix and CISA name, which is not the same as the consequence observed. It does not say whether the attacks reached the builds that fixed the 27 September flaws, although Citrix's affected range includes them. And Citrix's bulletin for the flaw, which Citrix calls the controlling statement, does not contain the word "exploit". The statement that Citrix has seen attacks is in a blog post.

Earlier briefings cover the 27 September flaws: the 22 days before the patch, the eight-flaw bulletin and the three-day clock and LevelBlue's fourth web shell disguise. This briefing covers what the third listing adds, at defender level: no trigger details and no exploit steps.

What the record says, and what it leaves out

CISA, CVE.org, NVD and Citrix each hold part of the record. The table puts them side by side and marks the gaps.

What the sources state about CVE-2026-88779. Read between 21:00 and 21:30 BST on 4 October 2026; wording in quotation marks is the source's own.

  1. Question
    Is it exploited?
    Stated
    CISA: added "based on evidence of active exploitation". CISA's data on the CVE.org record, stamped 19:34 UTC: exploitation "active". Citrix blog: it "has observed targeted attacks on unmitigated NetScaler deployments".
    Not stated
    By whom, how many, since when, against which builds, and how it was detected. Citrix's bulletin says nothing about exploitation.
  2. Question
    What does it do?
    Stated
    Citrix: "Memory overflow vulnerability leading to Denial of Service". Triggered repeatedly, "the service may remain unavailable". CISA: "could allow for a denial of service".
    Not stated
    Whether the attacks seen did only that. Citrix says it has "not identified an impact on the integrity of customer data", which is narrower than no code execution.
  3. Question
    Who is affected?
    Stated
    ADC and Gateway before 14.1-73.41 and before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS and NDcPP before 13.1-37.282. Only where the appliance is a SAML service provider or identity provider. Secure Private Access Hybrid deployments using NetScaler instances too.
    Not stated
    How many deployments meet the SAML precondition. The blog adds "in conjunction with Gateway or AAA functionality"; the bulletin does not. Neither page says whether the 15.1 Technology Preview or end-of-life 12.1 and 13.0 are affected.
  4. Question
    How is it fixed?
    Stated
    The four builds above. Customers who took the 27 September builds and meet the precondition should "upgrade your deployment again". Stopgap: Global Deny List signatures, in two version ranges.
    Not stated
    That the stopgap closes the flaw: the blog says it "can help to mitigate". Any known issue in the new builds.
  5. Question
    Any indicators?
    Stated
    Citrix: customers can block "suspicious IP addresses" with the blocklist and firewall rules.
    Not stated
    A single indicator, address, log pattern or scan for this flaw, in the bulletin or the blog.
  6. Question
    Who found it?
    Stated
    Cloud Software Group "thanks Bishop Fox and watchTowr".
    Not stated
    Who reported what, who saw the attacks, or whether either has published. We found no write-up of this CVE by either.
  7. Question
    What does CISA add?
    Stated
    Due 7 October. Forensic triage "Yes". Known ransomware use "Unknown". Notes list Citrix's two pages and CISA's two directive pages.
    Not stated
    A reason for the triage flag, any triage steps, or any indicator.

Two timestamps worth knowing. NVD's copy of CISA's exploitation field still reads "none", stamped 14:37 UTC, while CVE.org's copy of the same CISA data reads "active", stamped 19:34 UTC. A reader who checks NVD tonight sees the older answer. NVD also carries no CVSS 3.1 score yet. The only score anywhere is the 4.0 score assigned by Citrix as the CNA.

Denial of service of the front door

Denial of service sounds like the mild category. On a remote access gateway or an application delivery controller it is the front door going out. Citrix says that if the condition is triggered repeatedly, the service "may remain unavailable". Administrators quoted in secondary coverage, by Cybersecurity News and Cyberpress from Reddit threads we did not read, describe appliances already on 14.1-73.37 restarting in loops and, in one account, a watchdog rebooting the whole appliance after repeated crashes of an authentication process. Those are forum accounts relayed by news sites. They are not Citrix's findings, and they are labelled as such here.

The label is the vendor's assessment, not an observation. The table shows what Citrix's own titles and vectors have said about memory and denial-of-service flaws since June.

Citrix's own titles and CVSS 4.0 vectors for four flaws, from bulletins CTX696604 (30 June 2026), CTX697096 (27 September) and CTX697174 (4 October). Impact is on the vulnerable system: confidentiality, integrity, availability.

  1. Flaw
    CVE-2026-8452, 30 June
    Citrix's title
    Memory overflow leading to "unpredictable or erroneous behavior and Denial of Service"
    Impact and score
    High, Low, High. 8.8
  2. Flaw
    CVE-2026-88772, 27 September
    Citrix's title
    Memory overflow leading to "Remote Code Execution or Denial of Service"
    Impact and score
    High, High, High. 9.5
  3. Flaw
    CVE-2026-13474, 30 June
    Citrix's title
    "Denial of service via malformed HTTP/2 requests"
    Impact and score
    None, None, High. 8.7
  4. Flaw
    CVE-2026-88779, 4 October
    Citrix's title
    Memory overflow "leading to Denial of Service"
    Impact and score
    None, None, High. 8.7

Fairness first. For CVE-2026-88779 the title and the vector agree, and the vector has the same shape as Citrix's plain denial-of-service flaw from June. That was not true of CVE-2026-8452. Its title said denial of service while its vector rated confidentiality impact high, and Bishop Fox, in a post of 21 August, describes it as a heap overflow in the code that handles SAML single sign-on messages, "potentially" a route to remote code execution. CISA's catalogue text for that flaw, added on 26 August, says only that it "could lead to denial of service". The point is not that CVE-2026-88779 is the same bug. No source says it is. The point is that on this product line a denial-of-service label has understated a memory flaw before.

What is claimed beyond denial of service, and by whom. Kevin Beaumont, who is tracking NetScaler intrusions, wrote on 2 October that on one of his patched honeypots "it's running a downloaded (malware) binary", and on 4 October: "One of the threat actors is not trying to crash boxes." Neither Citrix nor CISA says so. Administrators quoted in secondary coverage describe command text in login attempts that, in one account, did not result in a download. These accounts do not match each other, and nobody has reconciled them. No source we read says CVE-2026-88779 allows code execution, and none rules it out.

The second friendly label is "patched". An appliance moved to 14.1-73.37 to meet CISA's 30 September due date is inside this flaw's affected range if SAML is configured on it, because the range is "before 14.1-73.41". Citrix's blog tells those customers to "upgrade your deployment again". A ticket that says "NetScaler patched, 30 September" can be true and still not answer the question.

How the third listing arrived

The order of events, from the primaries. On 27 September Citrix published bulletin CTX697096 and CISA listed CVE-2026-88771 and CVE-2026-88772 with a due date of 30 September. On 2 October a researcher posted at 19:01 UTC that his patched honeypots were crashing, and Citrix published interim guidance on a "newly observed" SAML issue (page timestamp 19:35 UTC) with no CVE and no fixed build. It said the issue was "independent of the vulnerabilities disclosed in CTX697096" and asked customers feeling the impact to contact support. Bulletin CTX697174 followed on 3 October Pacific time, and CVE.org gives 02:19 UTC on 4 October as the public date. CISA released catalogue 2026.10.04 at 18:52 UTC on 4 October.

Timeline from 26 September to 9 October 2026, to scale in days. CISA clocks: CVE-2026-88771 and 88772 added 27 September, due 30 September; CVE-2026-88779 added 4 October, due 7 October. Seven days between the listings; four days from the first due date to the third listing. Citrix: bulletin 27 September, interim SAML guidance 2 October, second bulletin 4 October. A researcher reports crashes on 2 October. No source gives the start of exploitation.
Drawn from the CISA catalogue 2026.10.04, Citrix bulletins CTX697096 and CTX697174, two Citrix community posts, the CVE.org record and one researcher's public posts. Clock times are UTC.

Derived from those stamps: the catalogue release came 16 hours 34 minutes after the CVE.org public date, and roughly 47 hours after Citrix's interim guidance. The first due date, 30 September, had passed four days before the third listing. CVE.org also shows the three IDs were reserved within a millisecond of one another at 07:14 UTC on 10 September, 17 days before the first bulletin. A reservation date is not a discovery date, and no source says when the flaw was found.

How CISA's own table reads this entry

BOD 26-04 sets the clock from four facts: whether the asset is publicly exposed, whether the CVE is in the catalogue, whether an adversary can automate the exploit, and the technical impact, total or partial control. CISA's own data on the CVE.org record gives this flaw automatable "yes" and technical impact "partial". The directive says "A denial-of-service attack is a form of limited control" over the component. In its Table 1 that combination, on an exposed asset in the catalogue, is row 2: three days, with no forensic triage.

NetScaler additions to the CISA catalogue since 26 August 2026, from the KEV feed version 2026.10.04. The quoted wording is CISA's own description.

  1. CVE
    CVE-2026-8452
    Added, due
    26 Aug, 29 Aug
    CISA's words on the consequence
    "could lead to denial of service"
    Triage
    No
  2. CVE
    CVE-2026-19490
    Added, due
    9 Sep, 12 Sep
    CISA's words on the consequence
    "may be able to bypass authentication"
    Triage
    Yes
  3. CVE
    CVE-2026-88771
    Added, due
    27 Sep, 30 Sep
    CISA's words on the consequence
    "execute arbitrary commands"
    Triage
    Yes
  4. CVE
    CVE-2026-88772
    Added, due
    27 Sep, 30 Sep
    CISA's words on the consequence
    "remote code execution or denial of service"
    Triage
    Yes
  5. CVE
    CVE-2026-88779
    Added, due
    4 Oct, 7 Oct
    CISA's words on the consequence
    "could allow for a denial of service"
    Triage
    Yes

The due date matches row 2. The triage flag does not: the record says "Yes", and CISA does not say why. Our count from the catalogue and from CISA's data on each CVE.org record, taken at about 21:15 BST: since the directive took effect on 10 June there have been 117 additions, 94 of them with a three-day deadline. Eight of those 94 are rated automatable and partial. Six of the eight carry "No". This flaw and a Microsoft SharePoint Server entry carry "Yes", and the earlier NetScaler denial-of-service flaw, CVE-2026-8452, carries "No".

One reading, which is ours and which CISA does not state: the flag may reflect that these are the same appliances already under a triage requirement from 27 September. The record differs in another way. The 27 September records said running Citrix's indicators in the console "may help identify indicators of exploitation". This record's notes field holds links and nothing else, and we found no indicators from Citrix for this flaw.

BOD 26-04 binds US federal civilian agencies only, and CISA "encourages all organizations" to prioritise catalogue flaws. The 7 October date is a benchmark for UK organisations, not an obligation.

Fixed builds, and one upgrade for all three

Citrix's own rule for the 27 September builds, in its blog, is to install one of them "or a later release in the same branch". The 4 October builds are later releases in those branches, so one move to them meets the build requirement of both bulletins. That is our reading of two Citrix statements, not a sentence Citrix has written. CVE-2026-88778, which is not in the catalogue, still needs its TCP configuration change from the 27 September bulletin, whatever the build.

Fixed builds from Citrix bulletins CTX697096 (27 September) and CTX697174 (4 October). Citrix writes the 13.1-FIPS and NDcPP build as 13.1.37.279 in the first bulletin and 13.1-37.282 in the second.

  1. Track
    ADC and Gateway 14.1
    27 September build
    14.1-73.37
    4 October build
    14.1-73.41
  2. Track
    ADC and Gateway 13.1
    27 September build
    13.1-64.23
    4 October build
    13.1-64.28
  3. Track
    ADC 14.1-FIPS
    27 September build
    14.1-73.37 FIPS
    4 October build
    14.1-73.41 FIPS
  4. Track
    ADC 13.1-FIPS and NDcPP
    27 September build
    13.1.37.279
    4 October build
    13.1-37.282
Version map, not to scale, for four NetScaler tracks. Below the 27 September build: open to CVE-2026-88771 and 88772, and open to 88779 if SAML is configured. From the 27 September build up to the 4 October build: fixed for the first two, open to 88779 if SAML is configured, with a Global Deny List range stated for 14.1 and 13.1 only. From the 4 October build: fixed for all three.
Drawn from Citrix bulletins CTX697096 and CTX697174 and Citrix's blog of 4 October. Build numbers are not evenly spaced.

Mitigation, and its limits. Citrix's blog lists Global Deny List signatures as a way to "help reduce exposure" while customers plan an upgrade. They need NetScaler Console, either on premises with Cloud Connect or the service, with "Virtual patching" enabled, and the appliance must sit in one of two ranges: 14.1-73.37 up to but not including 14.1-73.41, or 13.1-64.23 up to but not including 13.1-64.28. An appliance still on an older build is outside the stated range, and no range is stated for the FIPS and NDcPP tracks. The stopgap depends on NetScaler Console, a Citrix product, so it is open only to customers who already run it. Citrix gives two commands to confirm the signatures are present and counting hits. The blog says the signatures "can help to mitigate" the flaw. It does not say they close it.

A known issue is not mentioned. Citrix's 27 September blog warned that 13.1-64.23 may go into a cyclic reboot during upgrade for some configurations, and advised 13.1-64.24 for those. Neither 4 October page mentions that issue or any known issue for 13.1-64.28. Read the release notes for the build you pick.

The UK record

We read ncsc.gov.uk first. The NCSC's only NetScaler item is its alert of 28 September, which covers CVE-2026-88771 to CVE-2026-88778 and lists the builds fixed on 27 September. It does not mention CVE-2026-88779, and its news feed, read at about 21:05 BST on 4 October, carried nothing newer on NetScaler. NHS England Digital's alert list, read a minute later and checked again at 21:26 BST, shows CC-4858 of 28 September for the earlier zero-days and CC-4861 of 30 September as the most recent alert, and nothing for this CVE. We found no UK count of affected appliances, and the NCSC's September alert said it was working to understand the UK impact.

The NCSC's priority actions of 28 September are still the best UK guidance: isolate and replace where possible, investigate with the published indicators, install updates, re-enable, keep hunting, and report compromise. Its note that replacement "may cause service outage" is the nearest UK statement on the cost of the restart. CISA says the same of updating: it "may require downtime".

What to do, in the order worth doing

This list adds the third flaw to the order in the briefing on LevelBlue's report and keeps that briefing's compromise assessment. Specific strings and paths are in the vendors' own posts.

Take this with you

In the order worth doing

  • List every NetScaler ADC and Gateway you run: hardware, VPX and FIPS or NDcPP builds, both nodes of every high availability pair, and any instance behind Secure Private Access Hybrid. Record the exact build of each. Citrix upgrades its own managed cloud services.
  • Search each configuration for the two entries Citrix names: a SAML authentication action and a SAML identity provider profile. The bulletin says either one meets the precondition; the blog adds Gateway or AAA virtual servers. Treat any match as in scope until its owner shows otherwise, and record the appliances that do not match so the answer is on file.
  • Before any change to an in-scope appliance, preserve evidence: logs already forwarded off the box, core files, a support bundle and, for a virtual appliance, a snapshot. CISA says to preserve forensic evidence before applying updates, and the NCSC puts investigation before the update.
  • Upgrade to the 4 October build for the track, or a later one, as a single change that also covers the 27 September flaws. Citrix says customers who took the 27 September builds and use SAML should upgrade again.
  • Plan the restart. CISA warns that updating NetScaler may require downtime and the NCSC that replacement may cause service outage. For a high availability pair, decide the order of the nodes, upgrade both, and do not leave a standby on the old build to take over.
  • If the upgrade cannot happen today, the appliance is in Citrix's version range and you run NetScaler Console, make sure its virtual patching setting is enabled and confirm the Global Deny List signatures are present and counting hits. Treat that as a bridge, not a fix.
  • Look for unexpected restarts, crashes and core files since 27 September (our judgement, not a Citrix instruction): reboots nobody scheduled, the authentication process exiting, watchdog restart-limit messages in the system log, and files in the core directory. Line the times up against inbound login traffic and your identity provider's logs. A crash does not show whether an attempt worked.
  • Keep two kinds of log line apart. The word pitboss appears in the watchdog's own restart messages and also in the injected login text that earlier hunting advice for CVE-2026-88771 looks for. Our reading: a watchdog line in the system log and the same word inside a username field in an authentication event are different findings.
  • Keep the compromise assessment from the earlier briefings, because an update is not a cleanup, as Citrix says: compare accounts, web server configuration and web directories with a baseline from before September, check the system shell for special permission bits, sweep for hidden files, and check outbound connections against an allow-list.
  • If anything is found, rebuild rather than upgrade in place, restore only a configuration backup that predates the compromise, rotate what the configuration held, revoke Gateway sessions and look past the appliance.
  • Block known attacking source addresses only as a short bridge. Citrix says the blocklist and firewall rules can be used, publishes no addresses for this flaw, and addresses change.
  • If you are in the UK and think you were compromised, report it to the NCSC. NHS organisations should also report to the NHS England National CSOC. The NCSC Early Warning service is free.
  • After the upgrade or rebuild, record a baseline of the account list, the web server configuration and the web directories, and a list of which appliances carry SAML entries, so the next comparison is possible.

What we could not verify

The question this leaves

The label says availability, the due date says three days, and the triage flag says someone at CISA wants the appliance examined. Three signals, three readings, one appliance. For each NetScaler you run, which SAML entries does it carry, which build is it on, and how would anyone know whether it restarted last night?

Key facts

Sources

  1. PrimaryKEV JSON feed, catalogue version 2026.10.04, released 2026-10-04T18:52:56Z with 1,734 entries: the CVE-2026-88779 record, the earlier NetScaler records, and every count and date computed from the feedCISAaccessed 2026-10-04
  2. PrimaryAlert of 4 October 2026 adding CVE-2026-88779 to the catalogue, 'based on evidence of active exploitation'; read in fullCISAaccessed 2026-10-04
  3. PrimaryAlert on the 27 September NetScaler flaws, last revised 2 October: the statement that updating may require downtime, and the instruction to preserve evidence before updating; it does not mention CVE-2026-88779CISAaccessed 2026-10-04
  4. PrimaryBOD 26-04 of 10 June 2026 and its Table 1 (read as the published image): the three-day timeline, the definition of partial control that includes denial of service, and when forensic triage appliesCISAaccessed 2026-10-04
  5. PrimaryBOD 26-04 implementation guidance, updated 25 August 2026: how the KEV due date is set from the table, and how technical impact is judgedCISAaccessed 2026-10-04
  6. PrimaryCVE record read as JSON from the CVE Services API: Citrix's CNA container (title, versions, CVSS 4.0 vector, public date 02:19 UTC) and CISA's ADP container (exploitation active, automatable yes, technical impact partial, stamped 19:34 UTC)CVE Programaccessed 2026-10-04
  7. PrimaryNVD record read through the API at 21:03 BST: status Received, last modified 16:16 UTC, no NVD score, an older copy of CISA's exploitation fieldNational Vulnerability Databaseaccessed 2026-10-04
  8. PrimarySecurity bulletin CTX697174 for CVE-2026-88779, read in full as served and in a browser: description, SAML precondition, fixed builds, affected builds, acknowledgements and changelog; it does not contain the word exploitCitrix, Cloud Software Groupaccessed 2026-10-04
  9. PrimaryNetScaler Cyber Threat Intelligence blog on CVE-2026-88779, last updated 3 October Pacific time, read in a browser: the statement that Citrix has observed targeted attacks, the Global Deny List mitigation and its version ranges, and the instruction to upgrade againCitrix, Cloud Software Groupaccessed 2026-10-04
  10. PrimaryInterim guidance on a newly observed SAML issue, posted 2 October and updated 3 October: no CVE and no fixed build, independent of CTX697096, contact support if affectedCitrix, Cloud Software Groupaccessed 2026-10-04
  11. PrimarySecurity bulletin CTX697096 of 27 September for CVE-2026-88771 to CVE-2026-88778, re-read on 4 October: fixed builds, the statement that exploits have been observed, and a changelog that does not mention CVE-2026-88779Citrix, Cloud Software Groupaccessed 2026-10-04
  12. PrimaryBlog on the 27 September bulletin, last updated 30 September: the rule 'or a later release in the same branch', the 13.1-64.23 cyclic reboot known issue, and the statement that an update does not remove compromise artifactsCitrix, Cloud Software Groupaccessed 2026-10-04
  13. PrimarySecurity bulletin CTX696604 of 30 June 2026: Citrix's title and CVSS 4.0 vector for CVE-2026-8452 and for the denial-of-service flaw CVE-2026-13474Citrix, Cloud Software Groupaccessed 2026-10-04
  14. PrimaryNCSC alert of 28 September 2026 on CVE-2026-88771 to CVE-2026-88778: priority actions and the note that replacement may cause service outage; the NCSC news feed carried nothing newer on NetScaler at read timeNCSCaccessed 2026-10-04
  15. PrimaryCyber alert CC-4858 of 28 September on the NetScaler zero-days; the alert list showed CC-4861 of 30 September as the latest and nothing on CVE-2026-88779NHS England Digitalaccessed 2026-10-04
  16. PrimaryPost of 21 August 2026 on CVE-2026-8452: read for its summary and defender sections only; its description of the flaw as a heap overflow in SAML message handlingBishop Foxaccessed 2026-10-04
  17. PrimaryPublic post of 2 October, 19:01 UTC, read through the instance API: his patched 13.1 and 14.1 honeypots are crashing. One researcher's claim, not confirmed by Citrix or CISAKevin Beaumont (Mastodon)accessed 2026-10-04
  18. PrimaryPublic post of 2 October, 19:19 UTC: on one honeypot 'it's running a downloaded (malware) binary'. One researcher's claim, not confirmed by Citrix or CISAKevin Beaumont (Mastodon)accessed 2026-10-04
  19. PrimaryPublic post of 4 October, 12:25 UTC: 'One of the threat actors is not trying to crash boxes.' One researcher's claim, not confirmed by Citrix or CISAKevin Beaumont (Mastodon)accessed 2026-10-04
  20. Reported byReport of 3 October relaying Reddit accounts of reboot loops on 14.1-73.37 and a watchdog restart; the Reddit threads were not readCybersecurity Newsaccessed 2026-10-04
  21. Reported byReport of 3 October relaying administrator accounts of crashes, failovers and one logged command that did not complete a download; the forum posts were not readCyberpressaccessed 2026-10-04
  22. Reported byReport of 4 October on the bulletin and blog; no fact taken from it that is not in a Citrix pageSecurityOnlineaccessed 2026-10-04

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.