Skip to content

Security1 publisher2 min readPublished

Third NetScaler zero-day hits SAML appliances already patched against the first two

Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Citrix says the flaw is a high-severity memory overflow in NetScaler ADC and Gateway instances set up as a SAML service provider or identity provider.
  • Logs reviewed by affected admins showed authentication requests with shell commands hidden in the username field, written to fetch and run a malicious script.
  • Researcher Kevin Beaumont, who named the bug PitScaler 2, reported that one of his honeypots was running a downloaded malware binary.
  • A Reddit user who got hold of the script said it attempts to install web shells, persist across restarts and send the appliance's configuration and backups off the box, but warned there was no proof it had run.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any ADC or Gateway in a SAML provider role was open to this attack whatever its patch level against the earlier pair, so the previous update cycle left SAML deployments exposed.
  • contradiction Citrix's availability-only rating and the field evidence of code-execution attempts lead responders to different scopes: an outage ticket under one, a compromise investigation under the other.
  • decision Installing the fix does not settle whether a rebooted appliance ran the attackers' script, so owners have to assess each box that went down under attack in addition to updating it.

Citrix's public account of the flaw covers availability only. "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company wrote in a blog post [3]. "If the condition is triggered repeatedly, the service may remain unavailable." [15] On customer data, it wrote: "Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data." [4]

The payloads point further. Attackers who hide a download-and-run command in a login field [10] are trying for code execution, whatever rating the bug carries. SecurityWeek reported some indication that the flaw may be exploitable for remote code execution [6]. Beaumont saw exploitation attempts against honeypots that were already patched [7].

The sources differ in weight. Citrix's statement and CISA's catalog entry are on the record [3] [13]. The honeypot findings come from a named researcher [7] [8]. Everything known about what the script does traces to one Reddit user [11].

On exploitability: Citrix confirmed exploitation in the wild [1]. The trigger travels in authentication requests [10], and only appliances acting as a SAML service provider or identity provider are in scope [2]. Citrix confirms denial of service [3]. Code execution has been attempted, and the evidence that it can succeed comes from outside Citrix [6] [8].

The earlier pair, CVE-2026-88771 and CVE-2026-88772, had already pushed some customers to take appliances offline [5]. Updating against them did not help here: Reddit users said boxes already on the latest release kept rebooting [9]. Before fixes for the new bug arrived, admins described support queues lasting hours and interim workarounds that sometimes failed to stop the crashes [12].

CVE-2026-88779 is the sixth exploited NetScaler vulnerability CISA has added to its catalog in 2026 [14]. Three NetScaler zero-days have now surfaced within days of each other [2]. SecurityWeek's report does not name an actor behind the attacks [16], so on the public record the three are linked only by product and timing. Federal agencies got three days from listing to deadline [1].

What to watch

  • Whether Citrix revises its advisory to acknowledge code execution, given Beaumont's report of a honeypot running downloaded malware.
  • Forensic confirmation that the fetched script ran on any production appliance, including evidence of configuration or backup uploads.
  • A seventh NetScaler entry in CISA's catalog this year, or public attribution tying CVE-2026-88771, -88772 and -88779 to one group.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories