- Type
- Memory overflow leading to denial of service (CWE-119). Citrix says it has observed targeted attacks on unmitigated deployments and so far no impact on customer data integrity. [3][28]
- Exposure
- Only appliances configured as a SAML service provider (SP) or SAML identity provider (IdP) - the same applicability check Citrix gave for the 2 Oct issue: add authentication samlAction (SP) or add authentication samlIdPProfile (IdP). [3][28][2]
- Disclosure
- Citrix disclosed it on 3 Oct 2026 in bulletin CTX697174, crediting Bishop Fox and watchTowr. This is the CVE assigned to the SAML issue Citrix had described without a CVE since 2 Oct. [3][28]
- Status
- CISA added it to the KEV catalog on 4 Oct 2026 (catalog 2026.10.04), which confirms exploitation; federal remediation deadline 7 Oct 2026. Forensic triage required. Citrix has also released Global Deny List signatures as an interim mitigation on standard (non-FIPS) 14.1 and 13.1 appliances running the 27 Sep builds and managed through NetScaler Console. [21][3][28]
- Fix
- Fixed in 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 FIPS/NDcPP - newer builds than the CTX697096 fixes. SAML deployments that already upgraded to the September builds must upgrade again. [3][28]
CVE-2026-88779: Citrix NetScaler SAML memory overflow leading to DoS
CVE-2026-88779 is a Citrix NetScaler ADC and Gateway vulnerability: SAML memory overflow leading to DoS, rated CVSS 4.0 8.7 High. Citrix disclosed it on 3 October 2026 in bulletin CTX697174, crediting Bishop Fox and watchTowr, and says it has observed targeted attacks on unmitigated deployments with no impact on customer data integrity so far. It is the CVE behind the SAML issue Citrix had described without a CVE since 2 October. [3]
- CVE
- CVE-2026-88779
- Product
- Citrix NetScaler ADC and NetScaler Gateway
- Bulletin
- CTX697174 [3]
- Severity
- CVSS 4.0: 8.7 High
- Exploitation
- Exploited in the wild (targeted)
- CISA KEV
- Yes, added 4 Oct 2026, federal deadline 7 Oct 2026 [21]
- Disclosed
- Fixed builds
- 14.1-73.41, 13.1-64.28 and FIPS/NDcPP builds
CVE-2026-88779 vulnerability records
Official records for CVE-2026-88779, checked on 5 October 2026. The CVE record was published by the CNA (NetScaler) at 2026-10-04 04:16 UTC; NVD lists it as Undergoing Analysis, carrying the CNA-provided CVSS 4.0 8.7 HIGH (Secondary) and CWE-119. NVD has not scored it independently yet.
| CVSS 4.0 vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
|---|---|
| Weakness (NVD) | CWE-119 |
| NVD status | Undergoing Analysis (CNA score carried: CVSS 4.0 8.7 HIGH, Secondary) |
CVE-2026-88779 timeline
- Official advisory Validated
CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV
Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.
Dates validated against the KEV catalog feed on 29 Sep.
- Official advisory Deadline - upcoming
Deadline: CISA KEV federal remediation
Both CVEs were added to KEV on 27 Sep with a due date of 30 Sep, giving US federal agencies three days. The required action is to apply Citrix mitigations under BOD 26-04 and CISA's Forensics Triage Requirements, or stop using the product if mitigations are unavailable; the KEV notes say customers must conduct forensic triage. The KEV entry gives a date only (2026-09-30), no time of day. CISA's directive deadlines are conventionally 11:59 PM U.S. Eastern (23:59 EDT, 03:59 UTC on 1 Oct), and third-party KEV trackers treat the due date the same way, but CISA publishes no official time for KEV due dates - so the deadline was passed by 1 Oct 04:00 UTC at the latest. A deadline, not an event.
- Research
Poppelgaard checker v1.9 adds public indicators
Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.
Sources: [41]
- Official advisory
Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post
Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.
- Official advisory
CVE-2026-88779 assigned: bulletin CTX697174 with new fixed builds; Global Deny List interim mitigation
Citrix publishes bulletin CTX697174 for CVE-2026-88779 - the CVE behind the SAML issue it had described without a CVE since 2 Oct. Memory overflow, CVSS 4.0 8.7, DoS; Citrix credits Bishop Fox and watchTowr, says it has observed targeted attacks on unmitigated deployments, and has so far found no impact on customer data integrity. Fixed builds are newer than the September ones: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 FIPS/NDcPP - SAML deployments that upgraded on 27 Sep must upgrade again. Citrix also releases Global Deny List signatures as an interim mitigation for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console, and a blog explaining them. Only SAML SP or IdP configurations are affected (the same applicability check as the 2 Oct guidance).
- Official advisory
CISA adds CVE-2026-88779 to KEV - third exploited NetScaler CVE; federal deadline 7 Oct
CISA adds CVE-2026-88779 to the Known Exploited Vulnerabilities catalog (catalog version 2026.10.04, released 18:52 UTC), its third NetScaler entry of this campaign after CVE-2026-88771 and CVE-2026-88772 (both 27 Sep). CWE-119, due date 7 Oct 2026, required action: apply mitigations per vendor instructions under BOD 26-04 and CISA's Forensics Triage Requirements (forensicTriage = Yes), or discontinue use of the product if mitigations are unavailable; ransomware use Unknown. The KEV addition confirms the vulnerability is exploited, consistent with Citrix's "observed targeted attacks" wording.
- Community
Citrix forum: Console relabels to "NS Asset Delivery"; stat denylist command behaviour after patching (unconfirmed)
A customer reports in Citrix's CVE-2026-88779 forum thread (unconfirmed, no Citrix reply) two observations after patching to 13.1-64.28: on-prem NetScaler Console now shows "NS Asset Delivery" where it previously showed "Virtual Patching", and the verification command stat denylist global AAA_REQUEST - which worked before - returns "no such resource", although the signature version (v24) and Denylist flag are ON. Relevant to anyone verifying the Global Deny List mitigation with that command. A follow-up comment (04:25 UTC, same customer) offers the customer's own interpretation - that the GDL signatures apply per firmware to the CVEs known for that build, so an empty stat on the patched build is expected - explicitly not a Citrix statement. No IoCs either way. Verify mitigation state through NetScaler Console rather than one CLI command.
Sources: [109]
Questions about CVE-2026-88779
Is there a new NetScaler issue involving SAML?
Yes - it is now CVE-2026-88779. Citrix published guidance on 2 Oct 2026 for a newly observed, configuration-dependent issue in NetScaler deployments that use SAML authentication on a Gateway or AAA virtual server, and assigned CVE-2026-88779 on 3 Oct in bulletin CTX697174, crediting Bishop Fox and watchTowr. It is a memory overflow leading to denial of service (CVSS 4.0 8.7); Citrix says it has observed targeted attacks on unmitigated deployments and no impact on customer data integrity so far. CISA added it to the KEV catalog on 4 Oct with a 7 Oct deadline. Fixed builds are 14.1-73.41, 13.1-64.28 and the matching FIPS/NDcPP builds - newer than the CTX697096 fixes, so SAML deployments that upgraded in September must upgrade again. Beaumont reports his patched honeypots crashing, which is one researcher's observation. [2][3][77][78]
Which NetScaler vulnerabilities are exploited?
CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5), CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5) and, since 4 Oct 2026, CVE-2026-88779 (SAML memory overflow leading to DoS, CVSS 4.0 8.7). All three are in CISA's KEV catalog. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][21][3][66]
What fixes CVE-2026-88779, and why does stat denylist global AAA_REQUEST fail?
CVE-2026-88779 needs newer builds than the September fixes: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP (per bulletin CTX697174). SAML deployments that upgraded to the 27 Sep builds must upgrade again. As an interim measure, Citrix has released Global Deny List signatures for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console. A customer report in Citrix's forum (unconfirmed, no Citrix reply) says that after patching to 13.1-64.28, stat denylist global AAA_REQUEST returns "no such resource" or an empty result where it previously showed hits - the customer's own interpretation is that the Deny List signatures apply per firmware to the CVEs known for that build. Verify mitigation state through NetScaler Console rather than relying on that one command. [3][28]
Next steps
Related pages
References
| # | Source | Type | URL |
|---|---|---|---|
| 1 | Citrix - CTX697096 security bulletin (Sep 27) | Primary official advisories | https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html |
| 2 | Citrix community blog - Security Update: Guidance for NetScaler SAML Authentication Deployments (Oct 2; new issue, independent of CTX697096) | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/ |
| 3 | Citrix - CTX697174 security bulletin for CVE-2026-88779 (Oct 3; fixed builds 14.1-73.41, 13.1-64.28, FIPS/NDcPP) and the accompanying Citrix blog on Global Deny List mitigations | Primary official advisories | https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html |
| 4 | Citrix - CTX694799 Steps to Take if NetScaler ADC is Suspected to be Compromised | Primary official advisories | https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html |
| 5 | Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section; last updated Sep 30) verification pending | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ |
| 6 | Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcement | Primary official advisories | https://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/ |
| 7 | NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits) | Primary official advisories | https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc |
| 8 | CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27; updated Oct 2 with a SIGMA detection rule) | Primary official advisories | https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway |
| 9 | CISA Code & Media Analysis SIGMA rule - Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (TLP:CLEAR, test status; repo may be updated) | Primary official advisories | https://github.com/cisagov/SIGMA_Rules/blob/develop/CMA_SIGMA_Citrix_CVE_2026_8871.yaml |
| 10 | NCSC-NL advisory NCSC-2026-0394, version 1.0.1 (Sep 30; probability high, damage high; per-CVE scores and preconditions) | Primary official advisories | https://advisories.ncsc.nl/2026/ncsc-2026-0394.html |
| 11 | NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway | Primary official advisories | https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway |
| 12 | CSA Singapore - AL-2026-129 | Primary official advisories | https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/ |
| 13 | Canadian Centre for Cyber Security - AL26-024 | Primary official advisories | https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772 |
| 14 | CERT-FR alert CERTFR-2026-ALE-011 (Sep 28, updated Sep 30) | Primary official advisories | https://cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/ |
| 15 | CSSF (Luxembourg) communique - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Primary official advisories | https://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/ |
| 16 | CERT Quebec CERTQC-AVIS-2026-364 (Sep 28, TLP:CLEAR) | Primary official advisories | https://www.cyber.gouv.qc.ca/avis/certqc-avis-2026-364 |
| 17 | HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28) | Primary official advisories | https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928 |
| 18 | ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep; updated 3 Oct with the new SAML issue and confirmed Australian impacts) | Primary official advisories | https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products |
| 19 | BSI (Germany) - Citrix NetScaler: Systeme werden ueber ZeroDay-Schwachstellen angegriffen, BITS-H 2026-289305-1132, version 1.1 (Oct 1, TLP:CLEAR) | Primary official advisories | https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-289305-1032.pdf?__blob=publicationFile&v=4 |
| 20 | NCSC-FI / Traficom (Finland) - Citrix NetScaler vulnerabilities exploited in Finland (1 Oct; intrusions in Finland before the patches) | Primary official advisories | https://kyberturvallisuuskeskus.fi/en/news/citrix-netscaler-vulnerabilities-exploited-finland |
| 21 | CISA Known Exploited Vulnerabilities catalog (CVE-2026-88771 and -88772 added Sep 27, due Sep 30; CVE-2026-88779 added Oct 4, due Oct 7) | Primary official advisories | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 22 | CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27) | Primary official advisories | https://cert.europa.eu/publications/security-advisories/2026-014/ |
| 23 | DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29) | Primary official advisories | https://cert.dk/node/639 |
| 24 | NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScaler | Primary official advisories | https://digital.nhs.uk/cyber-alerts/2026/cc-4858 |
| 25 | CIRCL TR-100 - per-CVE configuration-check CLI commands | Primary official advisories | https://www.circl.lu/pub/tr-100/ |
| 26 | Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29) | Primary official advisories | https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262 |
| 27 | CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC) | Primary official advisories | https://www.cve.org/CVERecord?id=CVE-2026-88771 |
| 28 | Tenable Research Special Operations - FAQ on the reported Citrix NetScaler zero-days (Sep 27, last updated Oct 4 with CVE-2026-88779, KEV addition and GDL mitigations; also first to report the leaked NCSC-NL pre-notification TLP marking) | Technical research | https://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities |
| 29 | CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28) | Technical research | https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 |
| 30 | watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28) | Technical research | https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ |
| 31 | watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 |
| 32 | watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29) | Technical research | https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/ |
| 33 | watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 |
| 34 | Martin's Blog (mac.sploit.dk) - "NetScaler Needs More Than Another Patch" (Oct 2 08:00 CEST; opinion/analysis: platform posture, 15.1 Linux Tech Preview, what to demand at renewal) | Technical research | https://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/ |
| 35 | Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Technical research | https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway |
| 36 | Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29) | Technical research | https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances |
| 37 | Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29) | Technical research | https://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/ |
| 38 | Arctic Wolf - Citrix NetScaler Active Exploitation via CVE-2026-88771 (IoC pack, Sep 30) | Technical research | https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771 |
| 39 | Sygnia - Actively Exploited NetScaler Vulnerabilities (IR-based advisory, Sep 30) | Technical research | https://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/ |
| 40 | TENEX - What TENEX Observed Inside Active Exploitation of CVE-2026-88771 (Sep 30) | Technical research | https://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/ |
| 41 | Poppelgaard - NetScaler CTX697096/CTX697174 checker (free read-only script; v1.12 released Oct 4: CVE-2026-88779 checks, Beazley second-wave IPs, Gotham hunt list, webhook.site/dnshook.site; pyrlnk.cc removed per issue #3) | Technical research | https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker |
| 42 | Beazley Security second-wave indicators (BSL-A1216, updated Oct 3; carried in the Poppelgaard checker v1.12 via Gotham Technology Group, shared with permission) | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 43 | Poppelgaard - CVE-2026-88771 through CVE-2026-88778, what you should know and how to fix (Sep 28, last updated Oct 2) | Technical research | https://www.poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway |
| 44 | External malware analysis report (TLP:CLEAR, 2 Oct) - "Sliver C2 Implant Delivered via Citrix NetScaler Exploitation (CVE-2026-88771)"; independent static analysis, corroborated by Expel IR observation | Technical research | https://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027 |
| 45 | LevelBlue SpiderLabs (THOR team) - CVE-2026-88771 Observed Exploitation Artifacts and Hunt Indicators (Sep 30; own findings, not independently confirmed) | Technical research | https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators |
| 46 | Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPs | Technical research | https://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772 |
| 47 | Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28) | Technical research | https://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight |
| 48 | Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28) | Technical research | https://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml |
| 49 | SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29) | Technical research | https://github.com/SigmaHQ/sigma/pull/6352 |
| 50 | Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28) | Technical research | https://github.com/projectdiscovery/nuclei-templates/pull/17336 |
| 51 | eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29) | Technical research | https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772 |
| 52 | Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commands | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 53 | watchTowr (@watchtowrcyber) - "the watchTowr Labs team has now successfully reproduced this vulnerability" (Oct 3 X post; the vulnerability is not named in the text, understood to be the new SAML issue) | Technical research | https://x.com/watchtowrcyber/status/2106177591438958751 |
| 54 | watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics." | Technical research | https://x.com/watchtowrcyber/status/2103972792043479307 |
| 55 | CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes) | Technical research | https://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/ |
| 56 | GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28) | Telemetry and IoCs | https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation |
| 57 | GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timeline | Telemetry and IoCs | https://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771 |
| 58 | GreyNoise Visualizer - IP 149.104.78.141 | Telemetry and IoCs | https://viz.greynoise.io/ip/149.104.78.141 |
| 59 | GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | Telemetry and IoCs | https://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt |
| 60 | IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction") | Telemetry and IoCs | https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867 |
| 61 | VirusTotal - Perl file b9b0a438... (first submitted Oct 2 17:29 UTC; 3 of 75 engines by late 2 Oct); a Nextron THOR rule for CVE-2026-88771 and a community comment tie it to NetScaler exploitation | Telemetry and IoCs | https://www.virustotal.com/gui/file/b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63 |
| 62 | VirusTotal - ELF Sliver implant 0188b0eb... (31 of 75 engines; first submitted 2 Oct 11:49 UTC); served from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host, TLP:CLEAR malware analysis report | Telemetry and IoCs | https://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027 |
| 63 | Censys advisory - NetScaler exposure (42,735 hosts, Sep 28) | Telemetry and IoCs | https://censys.com/advisory/cve-2026-10747-2/ |
| 64 | Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 paths | Telemetry and IoCs | https://x.com/DefusedCyber/status/2104888497693708505 |
| 65 | Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoC | Telemetry and IoCs | https://x.com/lupovisdefence/status/2104595071362326680 |
| 66 | Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343729453093307 |
| 67 | Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoors | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343821114841048 |
| 68 | Beaumont, Sep 27 - Console check misses attempts when logs have rotated | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117345540231975640 |
| 69 | Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351107654208046 |
| 70 | Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351155381900219 |
| 71 | Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352481501981552 |
| 72 | Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352869498139711 |
| 73 | Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell names | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355208096613386 |
| 74 | Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117349313638958333 |
| 75 | Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355758746619146 |
| 76 | Beaumont, Oct 1 00:12 UTC - Arctic Wolf IoCs cover follow-up "spray and pray" activity, not the early-September actor | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117362758120876296 |
| 77 | Beaumont, Oct 2 19:01 UTC - patched 13.1 and 14.1 honeypots are crashing; "we may have #PitScaler 2 on our hands" (with two screenshots of an unattributed write-up) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372857146978531 |
| 78 | Beaumont, Oct 2 20:00 UTC - Citrix has published a blog on the new SAML issue (edited 20:15 UTC: "pitboss will execute" softened to "something will execute") | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117373090409884785 |
| 79 | Beaumont, Oct 2 19:02 UTC - "to be confirmed but it looks like the pitboss fix is bypassable" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372864244958549 |
| 80 | Beaumont, Oct 2 19:19 UTC - one patched honeypot is running a downloaded binary; "sprayed and prayed" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372929427365765 |
| 81 | Beaumont, Oct 2 23:25 UTC - "the policy citrix gave out doesn't work for me" (reply to O_P about a responder policy from Citrix Support) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117373896333693635 |
| 82 | Beaumont, Oct 3 01:40 UTC - "The Citrix support mitigations don't appear to work" (with a screenshot of an r/Citrix thread) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117374427108683985 |
| 83 | Cybersecurity News - "Citrix NetScaler Keeps Rebooting Following the 0-Day Patch" (Guru Baran, Oct 3; page shows only the date; secondary, Reddit-based) | Press and vendor coverage | https://cybersecuritynews.com/citrix-netscaler-0-day-patch/ |
| 84 | BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shells | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/ |
| 85 | BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalers | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ |
| 86 | The Stack (Oct 1) - Banks, gov'ts, telcos hit by hackers amid escalating NetScaler incident | Press and vendor coverage | https://www.thestack.technology/banks-govts-telcos-hit-by-hackers-amid-escalating-netscaler-incident-2/ |
| 87 | Help Net Security (Sep 30) - Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/ |
| 88 | Cloudflare changelog (Oct 1) - WAF Release 2026-10-01, Emergency: Citrix NetScaler CVE-2026-88771 managed rule | Press and vendor coverage | https://developers.cloudflare.com/changelog/post/2026-10-01-emergency-waf-release/ |
| 89 | Qualys ThreatPROTECT (Sep 28) - Citrix NetScaler zero-day vulnerabilities exploited in attacks | Press and vendor coverage | https://threatprotect.qualys.com/2026/09/28/citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-exploited-in-attacks-cve-2026-88771-cve-2026-88772/ |
| 90 | The Hacker News (Oct 1) - Citrix NetScaler post-exploitation payload creates superuser, maps web shell to CSS-like URLs (note: THN has also published unrelated third-party-appliance breach coverage sometimes mislinked to NetScaler) | Press and vendor coverage | https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html |
| 91 | BleepingComputer (Sep 28) - CISA orders feds to patch exploited Citrix flaws by Wednesday | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/ |
| 92 | SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-days | Press and vendor coverage | https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/ |
| 93 | The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bug | Press and vendor coverage | https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug |
| 94 | CyberScoop (Sep 28) - delayed-disclosure angle | Press and vendor coverage | https://cyberscoop.com/citrix-zero-days-delayed-disclosure/ |
| 95 | Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitation | Press and vendor coverage | https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation |
| 96 | Rapid7 ETR (Sep 28, last updated Sep 30) | Press and vendor coverage | https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/ |
| 97 | watchTowr FAQ (Sep 27-28) | Press and vendor coverage | https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/ |
| 98 | The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services | Press and vendor coverage | https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867 |
| 99 | Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28 and Sep 30 with pre- and post-disclosure activity and IoCs) | Press and vendor coverage | https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ |
| 100 | Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposed | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/ |
| 101 | Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/ |
| 102 | Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemer | Press and vendor coverage | https://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer |
| 103 | SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine) | Press and vendor coverage | https://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/ |
| 104 | Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notification | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/ |
| 105 | heise online (Sep 27) - New zero-day exploits in Citrix NetScaler | Press and vendor coverage | https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html |
| 106 | heise online (Oct 3 10:23 CEST) - "Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausfuehrung" (Dr. Christopher Kunz; cites Beaumont and a watchTowr reproduction claim, confirmed by watchTowr's own post the same day) | Press and vendor coverage | https://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html |
| 107 | Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers | Press and vendor coverage | https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix |
| 108 | Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT) | Press and vendor coverage | https://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem |
| 109 | Citrix community forum - "Update: ... Security Bulletin for CVE-2026-88779" thread (customer comments Oct 4-5 on Console labelling and stat denylist global AAA_REQUEST behaviour; unconfirmed, no Citrix reply) | Community | https://community.citrix.com/forums/topic/259166-update-citrix-netscaler-adc-and-citrix-netscaler-gateway-security-bulletin-for-cve-2026-88779/ |
| 110 | r/Citrix - "vulnerability scans causing netscaler reboots" thread (early Oct; anonymous comments, unverified) | Community | https://www.reddit.com/r/Citrix/comments/1wvwuno/vulnerability_scans_causing_netscaler_reboots/ |
| 111 | Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findings | Community | https://x.com/Maurice_Sec/status/2104541998858240487 |
| 112 | r/Citrix - "Netscaler leak?" thread (~Sep 26) | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ |
| 113 | r/Citrix - comment by asmOne (about 29 Sep; date approximate) quoting log-poison attempts | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/comment/pcub9wh/ |