Intel Hub

Threat intel

Citrix NetScaler has a third zero-day in weeks, and it may be more than a DoS.

On October 4, Citrix patched CVE-2026-88779, a memory buffer overflow in NetScaler SAML authentication. BleepingComputer reports it is already exploited, and the first DoS label may understate it.

Citrix patched CVE-2026-88779 on October 4, 2026. It is a memory buffer overflow in the SAML authentication path of NetScaler ADC and NetScaler Gateway. It carries a CVSS score of 8.7. Citrix confirmed targeted attacks against unpatched deployments. CISA added the flaw to its Known Exploited Vulnerabilities catalog. The federal remediation deadline is October 7, 2026.


Early reporting described the impact as denial of service. BleepingComputer says researchers found evidence pointing further. Attackers sent crafted authentication usernames containing shell commands that tried to pull payloads from 213.209.159[.]55. Researcher Kevin Beaumont reported that patched honeypots executed the downloaded malware. That suggests the bug may be more than a crash. Treat it as possible remote code execution until Citrix says otherwise.


This follows the NetScaler zero-days CYPEIRA covered earlier, where attackers deployed web shells and tunneling malware, reached root, stole credentials and moved into internal networks. NetScaler sits at the network edge and handles authentication. A foothold there is a path to everything behind it.


Affected builds are NetScaler ADC and Gateway before 14.1-73.41 and before 13.1-64.28. Fixed releases are 14.1-73.41 and 13.1-64.28. FIPS deployments need 14.1-73.41 FIPS, and NDcPP customers need 13.1-37.282.


Mitigation. Patch now to the fixed builds. Use Citrix Global Deny Lists to block the known malicious IP as a stopgap, not a substitute. Search authentication logs for usernames containing shell metacharacters or command strings. Check for outbound connections from appliances to 213.209.159[.]55 and for unexpected processes or files. If you find signs of compromise, rotate credentials that passed through the appliance and hunt for lateral movement.

Sign-in required.

The full encrypted event log and the mitigation steps are available after sign-in.