Overview
- Citrix released emergency NetScaler builds to fix CVE-2026-88779 and CISA added the flaw to its Known Exploited Vulnerabilities list with federal agencies ordered to mitigate by Oct. 7.
- The bug is a memory overflow in SAML handling that affects NetScaler ADC and NetScaler Gateway instances configured as a SAML service provider or identity provider and can cause service outages.
- Administrators and researchers have recorded repeated nsaaad and Pitboss crashes, authentication requests with crafted SAML usernames that include shell commands, and at least one patched honeypot running a downloaded binary.
- Citrix is providing Global Deny Lists and guidance to check SAML settings and it urges customers to install the new updates right away and to re-upgrade systems that were patched for earlier NetScaler fixes.
- Because NetScaler appliances are widely deployed and prior NetScaler zero-days have led to web shells and tunneling tools, defenders are advised to preserve memory and logs, rotate keys and credentials, and watch for follow-on access after initial compromise.