# Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 ("PitScaler 2") Exploited Against Appliances Patched Days Earlier (CISA KEV)

> CVE-2026-88779 is a memory overflow (CWE-119) in Citrix NetScaler ADC and Gateway appliances configured as a SAML SP or SAML IdP, exploited in the wild as a zero-day, including against appliances already patched for CVE-2026-88771/88772. Citrix rates it as denial-of-service, but researchers observed SAML authentication requests with shell commands in the username field fetching and running a payload, indicating possible remote code execution. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T19:00:39.086Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2923
- **ID:** TL-2026-2923
- **Severity:** HIGH (CVSS 8.7)
- **Category:** ZERO_DAY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-88779, CVE-2026-88771, CVE-2026-88772

## Description

CVE-2026-88779 is an unauthenticated memory overflow in the SAML handling of Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML service provider (add authentication samlAction) or SAML identity provider (add authentication samlIdPProfile) are vulnerable. Citrix security bulletin CTX697174 scores it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N, VA:H) and classifies it as a denial-of-service condition. Citrix stated it has observed targeted attacks on unmitigated NetScaler deployments and has identified no impact on the integrity of customer data.

Observed exploitation: crafted SAML authentication requests crash the nsaaad authentication daemon repeatedly until Pitboss restart limits are hit and the whole appliance reboots, producing unexplained reboots and VPN/SSO outages. Researcher Kevin Beaumont, who coined the name "PitScaler" (2026-09-28) for the preceding CVE-2026-88771/88772 zero-days and calls this one "PitScaler 2", saw exploitation of fully patched honeypots. Authentication requests carrying shell commands in the username field were seen downloading and executing scripts from 213.209.159.55; one honeypot ended up running a downloaded malware binary stored at /v. Reported attacker artifacts include web shell deployment attempts, attempts to exfiltrate configuration and backup files, and scripts intended to persist across reboots. Whether the overflow gives full RCE is not confirmed by Citrix; the evidence suggests it may.

Context: this is a follow-on to CVE-2026-88771 (improper input validation, command execution, CVSS v4 9.5) and CVE-2026-88772 (DTLS memory overflow, RCE/DoS, CVSS v4 9.5), added to CISA KEV on 2026-09-27 and fixed in 14.1-73.37 / 13.1-64.23. Appliances running those builds are still vulnerable to CVE-2026-88779 and need 14.1-73.41 / 13.1-64.28 or later. It is the sixth NetScaler flaw added to KEV in 2026. Targets reported in the hunt are government and finance; the Australian Cyber Security Centre confirmed Australian impact and recommended forensic checks back to 2026-09-04. No actor attribution, hashes or additional IOCs are published. Citrix offers generic IoC checks in NetScaler Console (requires telemetry) and Global Deny Lists; Citrix warns these may miss sophisticated intrusions.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1505.003 Web Shell
- T1005 Data from Local System
- T1499.004 Application or System Exploitation
- T1105 Ingress Tool Transfer

## Sources

- [Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier (SecurityWeek)](https://www.securityweek.com/exploitation-of-citrix-netscaler-zero-day-hits-appliances-patched-days-earlier/)
- [Citrix patches NetScaler SAML zero-day exploited in attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/)
- [Citrix Security Bulletin CTX697174 (CVE-2026-88779)](https://support.citrix.com/external/article/CTX697174)
- [Citrix: Understanding and addressing CVE-2026-88779 in NetScaler ADC and Gateway](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)
- [CISA Known Exploited Vulnerabilities Catalog (CVE-2026-88779 added 2026-10-04)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [PitScaler: Citrix NetScaler Zero-Day Vulnerabilities FAQ (Tenable)](https://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities)
- [Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks (Cyber Security News)](https://cybersecuritynews.com/citrix-netscaler-saml-0-day-vulnerability/)
- [CVE-2026-88779 Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV (DEV Community)](https://dev.to/threataft_dev/cve-2026-88779-citrix-netscaler-saml-memory-overflow-actively-exploited-cisa-kev-2jlf)
- [CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation (Bitsight)](https://www.bitsight.com/blog/critical-vulnerability-alert-cve-2026-88771-cve-2026-88772-citrix-netscaler-flaws-under-exploitation)
- [Citrix Security Bulletin CTX697096 (CVE-2026-88771/88772)](https://support.citrix.com/external/article/CTX697096)
- [Citrix NetScaler ADC: Neues SAML-Authentifizierungsproblem? (Borns IT- und Windows-Blog)](https://borncity.com/blog/2026/10/03/citrix-netscaler-adc-neues-saml-authentifizierungsproblem-3-10-2026)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2923
