Advisory summary
Another NetScaler flaw exploited: CVE-2026-88779 hits SAML setups; CISA and CERT-In say patch
Illustrative stock image via Unsplash. It does not depict the organisations named.
Days after two NetScaler zero-days, Citrix has fixed a third flaw, CVE-2026-88779, that it says is being used in targeted attacks on appliances set up for SAML login. CISA added it to its exploited list on 4 October; CERT-In rates it high.
01 / What happened
Citrix published security bulletin CTX697174 over the weekend of 3–4 October 2026 for CVE-2026-88779, a memory-handling flaw (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway. CISA added it to its Known Exploited Vulnerabilities catalogue on 4 October, which means it has evidence of attacks, and gave US federal agencies until 7 October to fix it. CERT-In published vulnerability note CIVN-2026-0492 on 7 October and rates it High.
It follows two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, fixed on 27 September (our report).
02 / Why it matters
CISA and CERT-In both describe the effect as a denial of service: a crafted request can knock the appliance over. NetScaler Gateway is the remote-access front door for many banks, government departments and IT firms in India, so taking it down cuts off staff and services. Citrix said it had observed targeted attacks on unmitigated appliances and that customer data integrity was not affected, according to Infosecurity Magazine and Tenable.
Reports that researchers are checking whether the bug can do more than crash the device are unconfirmed, and we are not repeating them as fact. Tenable said on 4 October that it knew of no public proof-of-concept exploit.
03 / Who is exposed
Affected builds, as listed by CERT-In:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
- NetScaler ADC FIPS before 14.1-73.41 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says only appliances configured as a SAML service provider or SAML identity provider are affected, according to Infosecurity Magazine and Tenable. Citrix-managed cloud services are not the target of these notes.
04 / Confirmed vs. claimed
Confirmed (official): the CVE, its CWE-119 class and denial-of-service effect, CISA's KEV listing on 4 October with a 7 October due date and a forensic-triage requirement, and the affected versions and High rating in CERT-In's note. Reported (security media citing Citrix): the SAML-only scope, the CVSS v4 score of 8.7, targeted attacks, and no impact on data integrity. Not known: who is behind the attacks and how many appliances were hit; CISA lists ransomware use as unknown. The exact date Citrix first published its bulletin differs between sources (3 or 4 October).
05 / What to do now
- Upgrade to 14.1-73.41 or 13.1-64.28 or later (or the matching FIPS/NDcPP builds) from Citrix's bulletin CTX697174.
- Check if you use SAML on the appliance. If you do and cannot patch at once, apply Citrix's interim mitigations from the bulletin.
- Look for signs of compromise, especially if you were late with the 27 September patches. CISA's listing asks agencies to do forensic triage, not just patch.
- Keep logs before rebooting or upgrading, so evidence is not lost.
- Indian organisations can report incidents to CERT-In at incident@cert-in.org.in, as its rules require.
Source log / 2026-1007-NS
- CISA — Known Exploited Vulnerabilities catalogue, CVE-2026-88779 (added 4 Oct 2026, due 7 Oct 2026) Primary
- CISA — KEV catalogue data feed (JSON) Primary
- CERT-In — Vulnerability note CIVN-2026-0492: Denial of service vulnerability in Citrix NetScaler ADC and Gateway (7 Oct 2026) Primary
- Citrix — Security bulletin CTX697174 Primary
- NVD — CVE-2026-88779 Primary
- Infosecurity Magazine — Citrix NetScaler zero-day (5 Oct 2026) Secondary
- Tenable — Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities (updated 4 Oct 2026) Secondary