Citrix has issued out-of-band builds to close CVE-2026-88779, a CVSS 8.7 memory-buffer issue in NetScaler ADC and NetScaler Gateway using SAML authentication with Gateway or AAA functionality, already abused in targeted zero-day denial-of-service attacks. Administrators on recently patched systems report nsaaad crashes and forced reboots with signs of possible remote code execution, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on Sunday with an October 7 mitigation deadline for FCEB agencies.

Affected products and fixed builds

The issue applies to customer-managed NetScaler ADC and NetScaler Gateway where SAML login is enabled through Gateway or AAA. Early Sunday morning Citrix published NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to address the zero-day. FIPS deployments are directed to 14.1-73.41 FIPS. NetScaler ADC FIPS and NDcPP customers on the 13.1 line are directed to 13.1-37.282. Citrix stated it had seen focused strikes against deployments without mitigations that could interrupt service, that repeated triggering could keep service offline, and that its review so far points to availability effects without identified effects on customer data integrity. The vendor is also offering Global Deny Lists to block access from recognized malicious addresses, while urging immediate installation of the new builds. Systems hardened recently against two actively abused flaws still need action. Citrix warned that any deployment updated with one of the releases named in the bulletin for CVE 2026-88771 through CVE 2026-88778 that also satisfies the SAML preconditions below should be updated again.

How to tell if exposed

Citrix describes the precondition as presence of SAML authentication configuration. Administrators can look for:


add authentication samlAction
add authentication samlIdPProfile

The first indicates operation as a SAML SP, the second as a SAML IdP. A later notice summarized the same condition as containing either an authentication samlAction or an authentication samlIdPProfile setting.

How the attacks surfaced

First accounts appeared on Friday, a correction dated 10/5/26 clarifies the start as Friday, not Thursday, after operators of recently updated devices noticed unexpected restarts. One operator said several client systems on 14.1-73.37 entered repeated forced reboots even though the newest protections available at that moment were installed. Others described matching behavior, including machines rebuilt from clean images. A separate account said nsaaad kept failing until the Pitboss supervisor hit its restart cap and rebooted the appliance. It was initially unclear if scanners were tripping a defect in fresh firmware or if adversaries were using an unknown weakness. An operator examining 14.1-73.37 systems then noted fabricated login names holding shell directives that would fetch a payload from 213.209.159[.]55, store it as /v, and run that file. Those requests showed up just before three confirmed nsaaad failure sequences on one box and were directed at multiple SAML authentication factors. The operator emphasized the evidence documented attempted use plus associated crashes without proving successful command execution. Additional operators confirmed identical nsaaad and Pitboss failure sequences, including on 14.1-73.37. While that analysis continued, Citrix said Friday its engineering and support groups were following a newly seen SAML-related problem in customer-managed estates, asked impacted users to open support cases, and stated it was distinct from earlier NetScaler disclosures.

Crash signs and possible execution

Citrix continues to categorize CVE-2026-88779 as denial-of-service, but field observations point to broader potential. Security researcher Kevin Beaumont reported patched 13.1 and 14.1 decoys failing after connections from multiple source addresses, calling it a possible further PitScaler event. He later reported one patched decoy was executing a fetched malicious binary, described the activity as untargeted spraying, and noted one decoy lacked a current certificate because he had allowed it to lapse. He also observed the new identifier was presented as a memory overflow causing denial of service, paralleling the early handling of CVE-2025-6543 before subsequent activity demonstrated remote execution capability. watchTowr Labs stated it had replicated the weakness after looking into decoy reports, without publishing method details.

Detection and mitigation

Treat any SAML-enabled ADC or Gateway as suspect until patched, especially with nsaaad restarts or unplanned reboots after Friday. Correlate authentication logs for unusual user values around crash times, isolate the appliance, preserve images and logs for review, apply 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 as appropriate for the train and compliance mode, and apply Global Deny Lists only as a supplement rather than a substitute for upgrading.

Technical background

This section is general background on this vulnerability class, not findings about this incident. Memory-safety failures in pre-authentication parsing can first appear as worker crashes and supervisor-initiated reboots, with execution potential depending on memory layout and mitigations. Operators often hunt that pattern with generic log and process checks, for example:


# Generic illustration only - not observed in this incident
ps -ef | grep -i nsaaad
grep -i -E 'crash|restart|pitboss' /var/log/generic-example.log
ss -tlnp | grep -E ':443|:80'

Such generic checks do not confirm exploitation of CVE-2026-88779 and do not replace vendor builds and guidance.