Overview
- Citrix released out‑of‑band firmware updates on October 4 for NetScaler ADC and Gateway (14.1‑73.41 and 13.1‑64.28) and published Global Deny Lists to block known malicious IPs.
- The bug, tracked as CVE‑2026‑88779, is a memory overflow that only affects appliances configured as a SAML service provider or SAML identity provider and can cause repeated crashes and service outages.
- Administrators and independent researchers observed exploitation against patched honeypots and production appliances, reporting nsaaad/Pitboss crashes, crafted SAML authentication requests that included shell commands, and at least one downloaded binary.
- CISA added the CVE to its KEV catalog and set an urgent remediation date for federal agencies which has pushed operators to preserve memory and logs, re‑inventory managed instances, and consider credential rotation and network blocks while they upgrade.
- The new zero‑day arrives after earlier NetScaler flaws this year were used to install web shells and tunneling tools, leaving tens of thousands of internet‑exposed appliances at heightened risk and forcing many administrators to reapply patches and recheck systems.