Threat reportZero-DayTL-2026-2923

Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 ("PitScaler 2") Exploited Against Appliances Patched Days Earlier (CISA KEV)

highACTIVE

Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 (TL-2026-2923), also tracked as PitScaler 2, is a high-severity zero-day vulnerability scored CVSS 8.7, first published 2026-10-05. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway, references 3 CVEs (CVE-2026-88779, CVE-2026-88771, CVE-2026-88772), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1105), and is covered by 9 detection rules and 8 indicators of compromise.

CVSS
8.7/10High
CVEs
3Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-2923

Threat ID
TL-2026-2923
Also known as
PitScaler 2
Severity
HIGH
CVSS
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
ZERO_DAY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance
Target regions
australia
Detection rules
9
Indicators of compromise
8
Updates
2026-10-05 · revalidated 1× · latest source

How Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 works

CVE-2026-88779 is a memory overflow (CWE-119) in Citrix NetScaler ADC and Gateway appliances configured as a SAML SP or SAML IdP, exploited in the wild as a zero-day, including against appliances already patched for CVE-2026-88771/88772. Citrix rates it as denial-of-service, but researchers observed SAML authentication requests with shell commands in the username field fetching and running a payload, indicating possible remote code execution. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline.

CVE-2026-88779 is an unauthenticated memory overflow in the SAML handling of Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML service provider (add authentication samlAction) or SAML identity provider (add authentication samlIdPProfile) are vulnerable. Citrix security bulletin CTX697174 scores it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N, VA:H) and classifies it as a denial-of-service condition. Citrix stated it has observed targeted attacks on unmitigated NetScaler deployments and has identified no impact on the integrity of customer data.

Observed exploitation: crafted SAML authentication requests crash the nsaaad authentication daemon repeatedly until Pitboss restart limits are hit and the whole appliance reboots, producing unexplained reboots and VPN/SSO outages. Researcher Kevin Beaumont, who coined the name "PitScaler" (2026-09-28) for the preceding CVE-2026-88771/88772 zero-days and calls this one "PitScaler 2", saw exploitation of fully patched honeypots. Authentication requests carrying shell commands in the username field were seen downloading and executing scripts from 213.209.159.55; one honeypot ended up running a downloaded malware binary stored at /v. Reported attacker artifacts include web shell deployment attempts, attempts to exfiltrate configuration and backup files, and scripts intended to persist across reboots. Whether the overflow gives full RCE is not confirmed by Citrix; the evidence suggests it may.

Context: this is a follow-on to CVE-2026-88771 (improper input validation, command execution, CVSS v4 9.5) and CVE-2026-88772 (DTLS memory overflow, RCE/DoS, CVSS v4 9.5), added to CISA KEV on 2026-09-27 and fixed in 14.1-73.37 / 13.1-64.23. Appliances running those builds are still vulnerable to CVE-2026-88779 and need 14.1-73.41 / 13.1-64.28 or later. It is the sixth NetScaler flaw added to KEV in 2026. Targets reported in the hunt are government and finance; the Australian Cyber Security Centre confirmed Australian impact and recommended forensic checks back to 2026-09-04. No actor attribution, hashes or additional IOCs are published. Citrix offers generic IoC checks in NetScaler Console (requires telemetry) and Global Deny Lists; Citrix warns these may miss sophisticated intrusions.

MITRE ATT&CK techniques used in TL-2026-2923

Collection

T1005 Data from Local System

Execution

T1059.004 Unix Shell

Command and Control

T1105 Ingress Tool Transfer

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Application or System Exploitation

Persistence

T1505.003 Web Shell

Affected products and versions in Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

  • Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway (configured as SAML SP or SAML IdP)
    Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS/NDcPP before 13.1-37.282
    Fixed in: 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282

Remediation for Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

Patches

  • NetScaler ADC/Gateway 14.1-73.41 and later
  • NetScaler ADC/Gateway 13.1-64.28 and later
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.282 and later

Immediate actions

  • Upgrade SAML SP/IdP NetScaler appliances to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP) or later
  • Apply Citrix Global Deny Lists to block known malicious sources
  • Check running config for 'add authentication samlAction' and 'add authentication samlIdPProfile' to find exposed appliances
  • Meet the CISA KEV deadline of 2026-10-07 for federal agencies

Workarounds

  • Citrix Global Deny Lists (temporary protection against known malicious sources only)

Longer-term hardening

  • Run compromise assessments on internet-exposed SAML-enabled appliances, looking back to 2026-09-04 (ACSC guidance)
  • Review NetScaler Console generic IoC output and engage forensic specialists, since coverage is incomplete
  • Re-upgrade appliances already patched for CVE-2026-88771/88772 (14.1-73.37 / 13.1-64.23 are insufficient)

CVEs associated with Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

CVE-2026-88779, CVE-2026-88771, CVE-2026-88772

Weaknesses (CWE) in Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

CWE-119

Timeline of Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

  • Australian Cyber Security Centre recommends forensic checks on NetScaler appliances dating back to this date
  • CISA adds CVE-2026-88771 and CVE-2026-88772 (NetScaler) to KEV; Citrix releases 14.1-73.37 / 13.1-64.23
  • Kevin Beaumont coins the name PitScaler for the first NetScaler zero-days
  • Reports emerge of unexpected reboots on recently patched NetScaler appliances (14.1-73.37) SAML-configured, with nsaaad crashing and pitboss reaching its restart limit.
  • Citrix publishes a notice acknowledging a newly observed issue; Kevin Beaumont's honeypots record SAML auth requests with shell commands in the username field and a payload fetched from 213.209.159.55.
  • watchTowr reproduces CVE-2026-88779 within hours of Citrix's disclosure (CTX697174); Bishop Fox and watchTowr credited alongside the vendor.
  • Reports of unexplained NetScaler reboots; Citrix publishes bulletin CTX697174 for CVE-2026-88779 with fixed versions
  • CISA adds CVE-2026-88779 to KEV; Citrix confirms targeted attacks on unmitigated deployments and releases patches
  • SecurityWeek and others report exploitation against patched appliances; Beaumont observes a honeypot running a downloaded malware binary
  • CISA remediation deadline for US federal agencies

Update history for TL-2026-2923

Sources cited for Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779

Detection coverage for TL-2026-2923

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2923 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2923

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats