CVE-2026-88779: Citrix NetScaler SAML memory overflow leading to DoS

CVE-2026-88779 is a Citrix NetScaler ADC and Gateway vulnerability: SAML memory overflow leading to DoS, rated CVSS 4.0 8.7 High. Citrix disclosed it on 3 October 2026 in bulletin CTX697174, crediting Bishop Fox and watchTowr, and says it has observed targeted attacks on unmitigated deployments with no impact on customer data integrity so far. It is the CVE behind the SAML issue Citrix had described without a CVE since 2 October. [3]

CVE
CVE-2026-88779
Product
Citrix NetScaler ADC and NetScaler Gateway
Bulletin
CTX697174 [3]
Severity
CVSS 4.0: 8.7 High
Exploitation
Exploited in the wild (targeted)
CISA KEV
Yes, added 4 Oct 2026, federal deadline 7 Oct 2026 [21]
Disclosed
Fixed builds
14.1-73.41, 13.1-64.28 and FIPS/NDcPP builds

CVE-2026-88779

Exploited in the wild (targeted) CVSS 4.0: 8.7 High
Type
Memory overflow leading to denial of service (CWE-119). Citrix says it has observed targeted attacks on unmitigated deployments and so far no impact on customer data integrity. [3][28]
Exposure
Only appliances configured as a SAML service provider (SP) or SAML identity provider (IdP) - the same applicability check Citrix gave for the 2 Oct issue: add authentication samlAction (SP) or add authentication samlIdPProfile (IdP). [3][28][2]
Disclosure
Citrix disclosed it on 3 Oct 2026 in bulletin CTX697174, crediting Bishop Fox and watchTowr. This is the CVE assigned to the SAML issue Citrix had described without a CVE since 2 Oct. [3][28]
Status
CISA added it to the KEV catalog on 4 Oct 2026 (catalog 2026.10.04), which confirms exploitation; federal remediation deadline 7 Oct 2026. Forensic triage required. Citrix has also released Global Deny List signatures as an interim mitigation on standard (non-FIPS) 14.1 and 13.1 appliances running the 27 Sep builds and managed through NetScaler Console. [21][3][28]
Fix
Fixed in 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 FIPS/NDcPP - newer builds than the CTX697096 fixes. SAML deployments that already upgraded to the September builds must upgrade again. [3][28]

CVE-2026-88779 vulnerability records

Official records for CVE-2026-88779, checked on 5 October 2026. The CVE record was published by the CNA (NetScaler) at 2026-10-04 04:16 UTC; NVD lists it as Undergoing Analysis, carrying the CNA-provided CVSS 4.0 8.7 HIGH (Secondary) and CWE-119. NVD has not scored it independently yet.

CVSS 4.0 vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Weakness (NVD)CWE-119
NVD statusUndergoing Analysis (CNA score carried: CVSS 4.0 8.7 HIGH, Secondary)

CVE-2026-88779 timeline

  1. Official advisory Validated

    CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV

    Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.

    Dates validated against the KEV catalog feed on 29 Sep.

    Sources: [8][21]

  2. Official advisory Deadline - upcoming

    Deadline: CISA KEV federal remediation

    Both CVEs were added to KEV on 27 Sep with a due date of 30 Sep, giving US federal agencies three days. The required action is to apply Citrix mitigations under BOD 26-04 and CISA's Forensics Triage Requirements, or stop using the product if mitigations are unavailable; the KEV notes say customers must conduct forensic triage. The KEV entry gives a date only (2026-09-30), no time of day. CISA's directive deadlines are conventionally 11:59 PM U.S. Eastern (23:59 EDT, 03:59 UTC on 1 Oct), and third-party KEV trackers treat the due date the same way, but CISA publishes no official time for KEV due dates - so the deadline was passed by 1 Oct 04:00 UTC at the latest. A deadline, not an event.

    Sources: [21][8][89][91]

  3. Research

    Poppelgaard checker v1.9 adds public indicators

    Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.

    Sources: [41]

  4. Official advisory

    Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post

    Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.

    Sources: [41][2][81][82]

  5. Official advisory

    CVE-2026-88779 assigned: bulletin CTX697174 with new fixed builds; Global Deny List interim mitigation

    Citrix publishes bulletin CTX697174 for CVE-2026-88779 - the CVE behind the SAML issue it had described without a CVE since 2 Oct. Memory overflow, CVSS 4.0 8.7, DoS; Citrix credits Bishop Fox and watchTowr, says it has observed targeted attacks on unmitigated deployments, and has so far found no impact on customer data integrity. Fixed builds are newer than the September ones: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 FIPS/NDcPP - SAML deployments that upgraded on 27 Sep must upgrade again. Citrix also releases Global Deny List signatures as an interim mitigation for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console, and a blog explaining them. Only SAML SP or IdP configurations are affected (the same applicability check as the 2 Oct guidance).

    Sources: [3][28][2]

  6. Official advisory

    CISA adds CVE-2026-88779 to KEV - third exploited NetScaler CVE; federal deadline 7 Oct

    CISA adds CVE-2026-88779 to the Known Exploited Vulnerabilities catalog (catalog version 2026.10.04, released 18:52 UTC), its third NetScaler entry of this campaign after CVE-2026-88771 and CVE-2026-88772 (both 27 Sep). CWE-119, due date 7 Oct 2026, required action: apply mitigations per vendor instructions under BOD 26-04 and CISA's Forensics Triage Requirements (forensicTriage = Yes), or discontinue use of the product if mitigations are unavailable; ransomware use Unknown. The KEV addition confirms the vulnerability is exploited, consistent with Citrix's "observed targeted attacks" wording.

    Sources: [21][3]

  7. Community

    Citrix forum: Console relabels to "NS Asset Delivery"; stat denylist command behaviour after patching (unconfirmed)

    A customer reports in Citrix's CVE-2026-88779 forum thread (unconfirmed, no Citrix reply) two observations after patching to 13.1-64.28: on-prem NetScaler Console now shows "NS Asset Delivery" where it previously showed "Virtual Patching", and the verification command stat denylist global AAA_REQUEST - which worked before - returns "no such resource", although the signature version (v24) and Denylist flag are ON. Relevant to anyone verifying the Global Deny List mitigation with that command. A follow-up comment (04:25 UTC, same customer) offers the customer's own interpretation - that the GDL signatures apply per firmware to the CVEs known for that build, so an empty stat on the patched build is expected - explicitly not a Citrix statement. No IoCs either way. Verify mitigation state through NetScaler Console rather than one CLI command.

    Sources: [109]

Questions about CVE-2026-88779

Is there a new NetScaler issue involving SAML?

Yes - it is now CVE-2026-88779. Citrix published guidance on 2 Oct 2026 for a newly observed, configuration-dependent issue in NetScaler deployments that use SAML authentication on a Gateway or AAA virtual server, and assigned CVE-2026-88779 on 3 Oct in bulletin CTX697174, crediting Bishop Fox and watchTowr. It is a memory overflow leading to denial of service (CVSS 4.0 8.7); Citrix says it has observed targeted attacks on unmitigated deployments and no impact on customer data integrity so far. CISA added it to the KEV catalog on 4 Oct with a 7 Oct deadline. Fixed builds are 14.1-73.41, 13.1-64.28 and the matching FIPS/NDcPP builds - newer than the CTX697096 fixes, so SAML deployments that upgraded in September must upgrade again. Beaumont reports his patched honeypots crashing, which is one researcher's observation. [2][3][77][78]

Which NetScaler vulnerabilities are exploited?

CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5), CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5) and, since 4 Oct 2026, CVE-2026-88779 (SAML memory overflow leading to DoS, CVSS 4.0 8.7). All three are in CISA's KEV catalog. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][21][3][66]

What fixes CVE-2026-88779, and why does stat denylist global AAA_REQUEST fail?

CVE-2026-88779 needs newer builds than the September fixes: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP (per bulletin CTX697174). SAML deployments that upgraded to the 27 Sep builds must upgrade again. As an interim measure, Citrix has released Global Deny List signatures for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console. A customer report in Citrix's forum (unconfirmed, no Citrix reply) says that after patching to 13.1-64.28, stat denylist global AAA_REQUEST returns "no such resource" or an empty result where it previously showed hits - the customer's own interpretation is that the Deny List signatures apply per firmware to the CVEs known for that build. Verify mitigation state through NetScaler Console rather than relying on that one command. [3][28]

Next steps

Related pages

References

#SourceTypeURL
1Citrix - CTX697096 security bulletin (Sep 27)Primary official advisorieshttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
2Citrix community blog - Security Update: Guidance for NetScaler SAML Authentication Deployments (Oct 2; new issue, independent of CTX697096)Primary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
3Citrix - CTX697174 security bulletin for CVE-2026-88779 (Oct 3; fixed builds 14.1-73.41, 13.1-64.28, FIPS/NDcPP) and the accompanying Citrix blog on Global Deny List mitigationsPrimary official advisorieshttps://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html
4Citrix - CTX694799 Steps to Take if NetScaler ADC is Suspected to be CompromisedPrimary official advisorieshttps://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
5Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section; last updated Sep 30) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
6Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcementPrimary official advisorieshttps://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/
7NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits)Primary official advisorieshttps://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc
8CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27; updated Oct 2 with a SIGMA detection rule)Primary official advisorieshttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
9CISA Code & Media Analysis SIGMA rule - Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (TLP:CLEAR, test status; repo may be updated)Primary official advisorieshttps://github.com/cisagov/SIGMA_Rules/blob/develop/CMA_SIGMA_Citrix_CVE_2026_8871.yaml
10NCSC-NL advisory NCSC-2026-0394, version 1.0.1 (Sep 30; probability high, damage high; per-CVE scores and preconditions)Primary official advisorieshttps://advisories.ncsc.nl/2026/ncsc-2026-0394.html
11NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayPrimary official advisorieshttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
12CSA Singapore - AL-2026-129Primary official advisorieshttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
13Canadian Centre for Cyber Security - AL26-024Primary official advisorieshttps://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
14CERT-FR alert CERTFR-2026-ALE-011 (Sep 28, updated Sep 30)Primary official advisorieshttps://cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/
15CSSF (Luxembourg) communique - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Primary official advisorieshttps://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/
16CERT Quebec CERTQC-AVIS-2026-364 (Sep 28, TLP:CLEAR)Primary official advisorieshttps://www.cyber.gouv.qc.ca/avis/certqc-avis-2026-364
17HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28)Primary official advisorieshttps://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928
18ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep; updated 3 Oct with the new SAML issue and confirmed Australian impacts)Primary official advisorieshttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
19BSI (Germany) - Citrix NetScaler: Systeme werden ueber ZeroDay-Schwachstellen angegriffen, BITS-H 2026-289305-1132, version 1.1 (Oct 1, TLP:CLEAR)Primary official advisorieshttps://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-289305-1032.pdf?__blob=publicationFile&v=4
20NCSC-FI / Traficom (Finland) - Citrix NetScaler vulnerabilities exploited in Finland (1 Oct; intrusions in Finland before the patches)Primary official advisorieshttps://kyberturvallisuuskeskus.fi/en/news/citrix-netscaler-vulnerabilities-exploited-finland
21CISA Known Exploited Vulnerabilities catalog (CVE-2026-88771 and -88772 added Sep 27, due Sep 30; CVE-2026-88779 added Oct 4, due Oct 7)Primary official advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
22CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27)Primary official advisorieshttps://cert.europa.eu/publications/security-advisories/2026-014/
23DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29)Primary official advisorieshttps://cert.dk/node/639
24NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScalerPrimary official advisorieshttps://digital.nhs.uk/cyber-alerts/2026/cc-4858
25CIRCL TR-100 - per-CVE configuration-check CLI commandsPrimary official advisorieshttps://www.circl.lu/pub/tr-100/
26Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29)Primary official advisorieshttps://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262
27CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC)Primary official advisorieshttps://www.cve.org/CVERecord?id=CVE-2026-88771
28Tenable Research Special Operations - FAQ on the reported Citrix NetScaler zero-days (Sep 27, last updated Oct 4 with CVE-2026-88779, KEV addition and GDL mitigations; also first to report the leaked NCSC-NL pre-notification TLP marking)Technical researchhttps://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities
29CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28)Technical researchhttps://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
30watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28)Technical researchhttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
31watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
32watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29)Technical researchhttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
33watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
34Martin's Blog (mac.sploit.dk) - "NetScaler Needs More Than Another Patch" (Oct 2 08:00 CEST; opinion/analysis: platform posture, 15.1 Linux Tech Preview, what to demand at renewal)Technical researchhttps://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/
35Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Technical researchhttps://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway
36Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29)Technical researchhttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
37Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29)Technical researchhttps://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/
38Arctic Wolf - Citrix NetScaler Active Exploitation via CVE-2026-88771 (IoC pack, Sep 30)Technical researchhttps://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771
39Sygnia - Actively Exploited NetScaler Vulnerabilities (IR-based advisory, Sep 30)Technical researchhttps://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/
40TENEX - What TENEX Observed Inside Active Exploitation of CVE-2026-88771 (Sep 30)Technical researchhttps://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/
41Poppelgaard - NetScaler CTX697096/CTX697174 checker (free read-only script; v1.12 released Oct 4: CVE-2026-88779 checks, Beazley second-wave IPs, Gotham hunt list, webhook.site/dnshook.site; pyrlnk.cc removed per issue #3)Technical researchhttps://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
42Beazley Security second-wave indicators (BSL-A1216, updated Oct 3; carried in the Poppelgaard checker v1.12 via Gotham Technology Group, shared with permission)Technical researchhttps://labs.beazley.security/advisories/BSL-A1216
43Poppelgaard - CVE-2026-88771 through CVE-2026-88778, what you should know and how to fix (Sep 28, last updated Oct 2)Technical researchhttps://www.poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway
44External malware analysis report (TLP:CLEAR, 2 Oct) - "Sliver C2 Implant Delivered via Citrix NetScaler Exploitation (CVE-2026-88771)"; independent static analysis, corroborated by Expel IR observationTechnical researchhttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
45LevelBlue SpiderLabs (THOR team) - CVE-2026-88771 Observed Exploitation Artifacts and Hunt Indicators (Sep 30; own findings, not independently confirmed)Technical researchhttps://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
46Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPsTechnical researchhttps://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772
47Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28)Technical researchhttps://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight
48Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28)Technical researchhttps://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml
49SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29)Technical researchhttps://github.com/SigmaHQ/sigma/pull/6352
50Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28)Technical researchhttps://github.com/projectdiscovery/nuclei-templates/pull/17336
51eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29)Technical researchhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
52Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commandsTechnical researchhttps://labs.beazley.security/advisories/BSL-A1216
53watchTowr (@watchtowrcyber) - "the watchTowr Labs team has now successfully reproduced this vulnerability" (Oct 3 X post; the vulnerability is not named in the text, understood to be the new SAML issue)Technical researchhttps://x.com/watchtowrcyber/status/2106177591438958751
54watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics."Technical researchhttps://x.com/watchtowrcyber/status/2103972792043479307
55CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes)Technical researchhttps://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/
56GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28)Telemetry and IoCshttps://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
57GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timelineTelemetry and IoCshttps://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771
58GreyNoise Visualizer - IP 149.104.78.141Telemetry and IoCshttps://viz.greynoise.io/ip/149.104.78.141
59GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptTelemetry and IoCshttps://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt
60IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction")Telemetry and IoCshttps://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
61VirusTotal - Perl file b9b0a438... (first submitted Oct 2 17:29 UTC; 3 of 75 engines by late 2 Oct); a Nextron THOR rule for CVE-2026-88771 and a community comment tie it to NetScaler exploitationTelemetry and IoCshttps://www.virustotal.com/gui/file/b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63
62VirusTotal - ELF Sliver implant 0188b0eb... (31 of 75 engines; first submitted 2 Oct 11:49 UTC); served from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host, TLP:CLEAR malware analysis reportTelemetry and IoCshttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
63Censys advisory - NetScaler exposure (42,735 hosts, Sep 28)Telemetry and IoCshttps://censys.com/advisory/cve-2026-10747-2/
64Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 pathsTelemetry and IoCshttps://x.com/DefusedCyber/status/2104888497693708505
65Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoCTelemetry and IoCshttps://x.com/lupovisdefence/status/2104595071362326680
66Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343729453093307
67Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoorsKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343821114841048
68Beaumont, Sep 27 - Console check misses attempts when logs have rotatedKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117345540231975640
69Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351107654208046
70Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351155381900219
71Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352481501981552
72Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352869498139711
73Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell namesKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355208096613386
74Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117349313638958333
75Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355758746619146
76Beaumont, Oct 1 00:12 UTC - Arctic Wolf IoCs cover follow-up "spray and pray" activity, not the early-September actorKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117362758120876296
77Beaumont, Oct 2 19:01 UTC - patched 13.1 and 14.1 honeypots are crashing; "we may have #PitScaler 2 on our hands" (with two screenshots of an unattributed write-up)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372857146978531
78Beaumont, Oct 2 20:00 UTC - Citrix has published a blog on the new SAML issue (edited 20:15 UTC: "pitboss will execute" softened to "something will execute")Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373090409884785
79Beaumont, Oct 2 19:02 UTC - "to be confirmed but it looks like the pitboss fix is bypassable"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372864244958549
80Beaumont, Oct 2 19:19 UTC - one patched honeypot is running a downloaded binary; "sprayed and prayed"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372929427365765
81Beaumont, Oct 2 23:25 UTC - "the policy citrix gave out doesn't work for me" (reply to O_P about a responder policy from Citrix Support)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373896333693635
82Beaumont, Oct 3 01:40 UTC - "The Citrix support mitigations don't appear to work" (with a screenshot of an r/Citrix thread)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117374427108683985
83Cybersecurity News - "Citrix NetScaler Keeps Rebooting Following the 0-Day Patch" (Guru Baran, Oct 3; page shows only the date; secondary, Reddit-based)Press and vendor coveragehttps://cybersecuritynews.com/citrix-netscaler-0-day-patch/
84BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shellsPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
85BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalersPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
86The Stack (Oct 1) - Banks, gov'ts, telcos hit by hackers amid escalating NetScaler incidentPress and vendor coveragehttps://www.thestack.technology/banks-govts-telcos-hit-by-hackers-amid-escalating-netscaler-incident-2/
87Help Net Security (Sep 30) - Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/
88Cloudflare changelog (Oct 1) - WAF Release 2026-10-01, Emergency: Citrix NetScaler CVE-2026-88771 managed rulePress and vendor coveragehttps://developers.cloudflare.com/changelog/post/2026-10-01-emergency-waf-release/
89Qualys ThreatPROTECT (Sep 28) - Citrix NetScaler zero-day vulnerabilities exploited in attacksPress and vendor coveragehttps://threatprotect.qualys.com/2026/09/28/citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-exploited-in-attacks-cve-2026-88771-cve-2026-88772/
90The Hacker News (Oct 1) - Citrix NetScaler post-exploitation payload creates superuser, maps web shell to CSS-like URLs (note: THN has also published unrelated third-party-appliance breach coverage sometimes mislinked to NetScaler)Press and vendor coveragehttps://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
91BleepingComputer (Sep 28) - CISA orders feds to patch exploited Citrix flaws by WednesdayPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
92SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-daysPress and vendor coveragehttps://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
93The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bugPress and vendor coveragehttps://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug
94CyberScoop (Sep 28) - delayed-disclosure anglePress and vendor coveragehttps://cyberscoop.com/citrix-zero-days-delayed-disclosure/
95Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitationPress and vendor coveragehttps://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
96Rapid7 ETR (Sep 28, last updated Sep 30)Press and vendor coveragehttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
97watchTowr FAQ (Sep 27-28)Press and vendor coveragehttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
98The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesPress and vendor coveragehttps://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
99Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28 and Sep 30 with pre- and post-disclosure activity and IoCs)Press and vendor coveragehttps://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
100Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposedPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
101Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
102Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemerPress and vendor coveragehttps://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer
103SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine)Press and vendor coveragehttps://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/
104Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notificationPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/
105heise online (Sep 27) - New zero-day exploits in Citrix NetScalerPress and vendor coveragehttps://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html
106heise online (Oct 3 10:23 CEST) - "Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausfuehrung" (Dr. Christopher Kunz; cites Beaumont and a watchTowr reproduction claim, confirmed by watchTowr's own post the same day)Press and vendor coveragehttps://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html
107Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersPress and vendor coveragehttps://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix
108Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT)Press and vendor coveragehttps://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem
109Citrix community forum - "Update: ... Security Bulletin for CVE-2026-88779" thread (customer comments Oct 4-5 on Console labelling and stat denylist global AAA_REQUEST behaviour; unconfirmed, no Citrix reply)Communityhttps://community.citrix.com/forums/topic/259166-update-citrix-netscaler-adc-and-citrix-netscaler-gateway-security-bulletin-for-cve-2026-88779/
110r/Citrix - "vulnerability scans causing netscaler reboots" thread (early Oct; anonymous comments, unverified)Communityhttps://www.reddit.com/r/Citrix/comments/1wvwuno/vulnerability_scans_causing_netscaler_reboots/
111Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findingsCommunityhttps://x.com/Maurice_Sec/status/2104541998858240487
112r/Citrix - "Netscaler leak?" thread (~Sep 26)Communityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/
113r/Citrix - comment by asmOne (about 29 Sep; date approximate) quoting log-poison attemptsCommunityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/comment/pcub9wh/