Citrix disclosed CVE-2026-88779 on 4 October 2026: a memory overflow, scored 8.7, in NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider alongside Gateway or AAA. It is being exploited in targeted attacks. CISA added it to the Known Exploited Vulnerabilities catalogue on the 5th, with a federal deadline of the 7th.
That answers a question we left open three days ago.
What we said, and what it turned out to be
On 3 October we wrote about NetScaler customers whose appliances kept restarting after installing 14.1-73.37, the emergency build for two exploited 9.5s. Citrix had said it was tracking a newly seen SAML issue. There was no CVE, no published root cause and no release number, and the bulletin people were reading had not been updated to mention any of it.
We said two conclusions were tempting and both were wrong: that a rebooting appliance meant you had been breached, and that 14.1-73.37 had somehow reopened the original flaws.
Both still hold, and the actual answer is a third thing neither of us had the evidence for. The reboots were not a defect in the patch. They were a separate vulnerability being exploited, on appliances that had just been updated — which is why they appeared to follow the update, and why rolling back would have made things worse rather than better.
Six crashes
The mechanism is now documented, and it matches what administrators described.
An attacker sends a crafted request that crashes the service handling SAML authentication. The crash repeats on each attempt. On the sixth crash, the watchdog that exists to notice a service dying too often does what it is designed to do and restarts the appliance.
That is the whole exploit. There is no code execution, no shell, no data taken. Citrix's own assessment is that the issue affects service availability and that it has not identified an impact on the integrity of customer data.
It also explains the detail that confused people most: several reports described the reboots starting after a vulnerability scan. A scan against your own gateway sends exactly the kind of malformed authentication traffic this bug responds to. Administrators doing the responsible post-patch check were, in some cases, triggering it themselves.
A denial of service on this box is not a minor finding
An 8.7 that only crashes things reads like a lesser problem than the 9.5s that preceded it. On this class of device that framing is wrong.
NetScaler Gateway is how remote workers reach everything. When the SAML service dies, authentication stops — which means nobody logs in, and when the box reboots, every session on it ends. An attacker who can do that on demand, repeatedly, from outside, does not need code execution to take a company offline.
The targeting makes the same point. Citrix describes targeted attacks rather than mass exploitation, and reporting has linked earlier intrusions in this series to suspected state-sponsored activity. Nobody burns a zero-day on a gateway to make it reboot unless the outage is the objective, or unless the reboot is useful for something else — clearing memory-resident evidence, for instance, which is worth considering on an appliance where forensics live in RAM.
Three in a week
This is the third actively exploited NetScaler zero-day disclosed in under a week, after CVE-2026-88771 and CVE-2026-88772.
That pattern is worth naming without overreading it. It can mean a researcher or an actor is working systematically through one codebase and shipping findings as they land. It can mean one intrusion led investigators to the rest. What it does mean for anyone running these appliances is that the emergency window did not close when the first patch went on, and planning as though it did is the mistake available this week.
What to do
- Upgrade to 14.1-73.41 or 13.1-64.28, or the matching FIPS builds — 14.1-73.41 FIPS, or 13.1-37.282 for FIPS and NDcPP. The federal deadline was the 7th; there is no reason for anyone else to be slower.
- If you cannot upgrade today, apply Citrix's signatures through the Global Deny List. They block known malicious addresses, which is a stopgap against the campaign rather than a fix for the flaw.
- Check whether you are exposed at all. This needs SAML configured as service provider or identity provider, with Gateway or AAA. If that is not your configuration, this specific CVE is not yours to chase.
- Keep hunting on anything that was internet-facing before the first patch. None of this changes the earlier position: patching stopped new use of 88771 and 88772, and did nothing about what was placed before it.
- Collect state before the next restart, not after. On an appliance where the watchdog reboots the box, the evidence you want is gone by the time you look.
What is not established
- Who is exploiting it. Citrix describes targeted attacks and names no actor.
- Whether the reboots reported by every affected customer were this CVE, or whether some were ordinary instability after an upgrade. The two are indistinguishable from the outside.
- Whether the three zero-days in this series share a researcher, an actor, or only a codebase.
- How long CVE-2026-88779 was being used before Citrix documented it.