Threat reportZero-DayTL-2026-2923
Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 ("PitScaler 2") Exploited Against Appliances Patched Days Earlier (CISA KEV)
Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 (TL-2026-2923), also tracked as PitScaler 2, is a high-severity zero-day vulnerability scored CVSS 8.7, first published 2026-10-05. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway, references 3 CVEs (CVE-2026-88779, CVE-2026-88771, CVE-2026-88772), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1105), and is covered by 9 detection rules and 8 indicators of compromise.
- CVSS
- 8.7/10High
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-2923
- Threat ID
- TL-2026-2923
- Also known as
- PitScaler 2
- Severity
- HIGH
- CVSS
- 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- ZERO_DAY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance
- Target regions
- australia
- Detection rules
- 9
- Indicators of compromise
- 8
- Updates
- 2026-10-05 · revalidated 1× · latest source
How Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 works
CVE-2026-88779 is a memory overflow (CWE-119) in Citrix NetScaler ADC and Gateway appliances configured as a SAML SP or SAML IdP, exploited in the wild as a zero-day, including against appliances already patched for CVE-2026-88771/88772. Citrix rates it as denial-of-service, but researchers observed SAML authentication requests with shell commands in the username field fetching and running a payload, indicating possible remote code execution. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline.
CVE-2026-88779 is an unauthenticated memory overflow in the SAML handling of Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML service provider (add authentication samlAction) or SAML identity provider (add authentication samlIdPProfile) are vulnerable. Citrix security bulletin CTX697174 scores it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N, VA:H) and classifies it as a denial-of-service condition. Citrix stated it has observed targeted attacks on unmitigated NetScaler deployments and has identified no impact on the integrity of customer data.
Observed exploitation: crafted SAML authentication requests crash the nsaaad authentication daemon repeatedly until Pitboss restart limits are hit and the whole appliance reboots, producing unexplained reboots and VPN/SSO outages. Researcher Kevin Beaumont, who coined the name "PitScaler" (2026-09-28) for the preceding CVE-2026-88771/88772 zero-days and calls this one "PitScaler 2", saw exploitation of fully patched honeypots. Authentication requests carrying shell commands in the username field were seen downloading and executing scripts from 213.209.159.55; one honeypot ended up running a downloaded malware binary stored at /v. Reported attacker artifacts include web shell deployment attempts, attempts to exfiltrate configuration and backup files, and scripts intended to persist across reboots. Whether the overflow gives full RCE is not confirmed by Citrix; the evidence suggests it may.
Context: this is a follow-on to CVE-2026-88771 (improper input validation, command execution, CVSS v4 9.5) and CVE-2026-88772 (DTLS memory overflow, RCE/DoS, CVSS v4 9.5), added to CISA KEV on 2026-09-27 and fixed in 14.1-73.37 / 13.1-64.23. Appliances running those builds are still vulnerable to CVE-2026-88779 and need 14.1-73.41 / 13.1-64.28 or later. It is the sixth NetScaler flaw added to KEV in 2026. Targets reported in the hunt are government and finance; the Australian Cyber Security Centre confirmed Australian impact and recommended forensic checks back to 2026-09-04. No actor attribution, hashes or additional IOCs are published. Citrix offers generic IoC checks in NetScaler Console (requires telemetry) and Global Deny Lists; Citrix warns these may miss sophisticated intrusions.
MITRE ATT&CK techniques used in TL-2026-2923
Collection
Execution
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Persistence
Affected products and versions in Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
- Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway (configured as SAML SP or SAML IdP)
Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS/NDcPP before 13.1-37.282
Fixed in: 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282
Remediation for Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
Patches
- NetScaler ADC/Gateway 14.1-73.41 and later
- NetScaler ADC/Gateway 13.1-64.28 and later
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later
- NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.282 and later
Immediate actions
- Upgrade SAML SP/IdP NetScaler appliances to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP) or later
- Apply Citrix Global Deny Lists to block known malicious sources
- Check running config for 'add authentication samlAction' and 'add authentication samlIdPProfile' to find exposed appliances
- Meet the CISA KEV deadline of 2026-10-07 for federal agencies
Workarounds
- Citrix Global Deny Lists (temporary protection against known malicious sources only)
Longer-term hardening
- Run compromise assessments on internet-exposed SAML-enabled appliances, looking back to 2026-09-04 (ACSC guidance)
- Review NetScaler Console generic IoC output and engage forensic specialists, since coverage is incomplete
- Re-upgrade appliances already patched for CVE-2026-88771/88772 (14.1-73.37 / 13.1-64.23 are insufficient)
CVEs associated with Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
Weaknesses (CWE) in Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
Timeline of Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
- Australian Cyber Security Centre recommends forensic checks on NetScaler appliances dating back to this date
- CISA adds CVE-2026-88771 and CVE-2026-88772 (NetScaler) to KEV; Citrix releases 14.1-73.37 / 13.1-64.23
- Kevin Beaumont coins the name PitScaler for the first NetScaler zero-days
- Reports emerge of unexpected reboots on recently patched NetScaler appliances (14.1-73.37) SAML-configured, with nsaaad crashing and pitboss reaching its restart limit.
- Citrix publishes a notice acknowledging a newly observed issue; Kevin Beaumont's honeypots record SAML auth requests with shell commands in the username field and a payload fetched from 213.209.159.55.
- watchTowr reproduces CVE-2026-88779 within hours of Citrix's disclosure (CTX697174); Bishop Fox and watchTowr credited alongside the vendor.
- Reports of unexplained NetScaler reboots; Citrix publishes bulletin CTX697174 for CVE-2026-88779 with fixed versions
- CISA adds CVE-2026-88779 to KEV; Citrix confirms targeted attacks on unmitigated deployments and releases patches
- SecurityWeek and others report exploitation against patched appliances; Beaumont observes a honeypot running a downloaded malware binary
- CISA remediation deadline for US federal agencies
Update history for TL-2026-2923
- 2026-10-05 — CVE-2026-88779: Citrix NetScaler ADC/Gateway Zero-Day Exploited Against SAML Deployments: What changed No severity/exploitability/status change (already HIGH / ACTIVE). Exploitation is now dated to at least 2026-10-01 (earlier than the 2026-10-03 disclosure), and exploitation is documented as hitting SAML-configured appliances o
Sources cited for Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier (SecurityWeek)
- Citrix patches NetScaler SAML zero-day exploited in attacks (BleepingComputer)
- Citrix Security Bulletin CTX697174 (CVE-2026-88779)
- Citrix: Understanding and addressing CVE-2026-88779 in NetScaler ADC and Gateway
- CISA Known Exploited Vulnerabilities Catalog (CVE-2026-88779 added 2026-10-04)
- PitScaler: Citrix NetScaler Zero-Day Vulnerabilities FAQ (Tenable)
- Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks (Cyber Security News)
- CVE-2026-88779 Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV (DEV Community)
- CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation (Bitsight)
- Citrix Security Bulletin CTX697096 (CVE-2026-88771/88772)
- Citrix NetScaler ADC: Neues SAML-Authentifizierungsproblem? (Borns IT- und Windows-Blog)
Detection coverage for TL-2026-2923
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2923 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2923
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.