Cybersecurity

Citrix NetScaler Zero-Days: What Indian Firms Must Do

Affix Center · · 5 min read

Network cables in a data centre rack, illustrating the Citrix NetScaler zero-day patches of October 2026

In short: Citrix has patched a third actively exploited NetScaler flaw in about a week. CVE-2026-88779 affects NetScaler ADC and Gateway appliances that use SAML login, and it hit systems that were already patched for the earlier two flaws. If your organisation runs NetScaler, check the build and update now.

If your team patched NetScaler last week and moved on, this news is for you. The patch you installed a few days ago is no longer enough. Attackers found another weakness in the same product, and appliances that were fully up to date began rebooting on their own.

What Happened

NetScaler ADC and NetScaler Gateway are Citrix products that many banks, large companies and government bodies use for remote access, single sign-on and load balancing. They sit at the edge of the network, facing the internet, which makes them a regular target.

The timeline, as reported by security news outlets:

  • 28 September 2026: Citrix disclosed two critical flaws, CVE-2026-88771 and CVE-2026-88772, and said they were already being exploited, according to CSO Online. The fixes were in builds 14.1-73.37 and 13.1-64.23. SecurityWeek reports that the pair has been nicknamed "PitScaler".
  • Friday, 2 October 2026: some fully patched appliances started rebooting. SecurityWeek reported that logs showed login requests with shell commands hidden in the username field.
  • The weekend of 3 and 4 October 2026: CyberScoop reported that Citrix alerted customers on Friday and released a fix on Saturday. Citrix published security bulletin CTX697174 for the new flaw, CVE-2026-88779. The US agency CISA then added it to its Known Exploited Vulnerabilities catalog and told US federal agencies to fix it by 7 October 2026.

The Hacker News and BleepingComputer describe CVE-2026-88779 as a memory overflow flaw with a CVSS score of 8.7. The researchers credited with reporting it are from Bishop Fox and watchTowr.

Who Is Affected

According to the Citrix bulletin as quoted by The Hacker News, the issue affects customer-managed NetScaler deployments on supported versions when one condition is met: the appliance is set up for SAML authentication, either as a SAML service provider or as a SAML identity provider. In the configuration this shows up as one of these lines:

  • add authentication samlAction
  • add authentication samlIdPProfile

SAML is widely used for single sign-on with Microsoft Entra ID, Okta and similar identity services, so this set-up is common.

Product lineFixed build for CVE-2026-88779
NetScaler ADC and Gateway 14.114.1-73.41 and later
NetScaler ADC and Gateway 13.113.1-64.28 and later
NetScaler ADC 14.1-FIPS14.1-73.41 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1-37.282 and later

These build numbers are as reported by The Hacker News and BleepingComputer on 4 and 5 October 2026. Always confirm against the Citrix bulletin itself before you plan the upgrade, because vendors sometimes revise advisories.

What Is Still Unclear

Sources do not fully agree on how serious the new flaw is on its own.

  • Citrix describes the impact as denial of service: the service can crash, and if the attack is repeated it can stay down.
  • BleepingComputer reported that researchers saw signs of attackers trying to run commands and download files on appliances.
  • SecurityWeek reported that watchTowr later assessed CVE-2026-88779 as a denial of service flaw only, and suggested it may be used to crash systems as part of attacks on the earlier flaw, CVE-2026-88771.

For a business, the practical point is the same in all three readings. Your remote access gateway can be knocked offline, and the earlier two flaws were rated critical. Treat the whole set as urgent.

Why This Matters for Indian Organisations

A NetScaler outage is not a small IT issue. It can stop work-from-home staff, branch users and vendors from logging in at all. For a bank, an insurer, a hospital or a government department, that is a service disruption that customers and citizens notice.

There is also a compliance angle. Guidance issued by CERT-In in May 2026, as reported by The Hacker News and Infosecurity Magazine, recommends that known exploited flaws on internet-facing systems be fixed or contained within 12 hours. A NetScaler gateway is exactly that kind of system. Separately, CERT-In directions require specified cyber incidents to be reported within six hours of being noticed. If you find signs of compromise, read our CERT-In 6-hour reporting checklist and check your obligations with your compliance adviser.

What to Do Now

  1. Find every NetScaler. List all ADC and Gateway appliances, including those at disaster recovery sites and those managed by a vendor or hosting provider.
  2. Check the build. Compare the running build with the fixed builds in the table. Anything lower needs action, even if you patched last week.
  3. Check for SAML. Search the configuration for the two SAML lines above. If either is present, the appliance is exposed to CVE-2026-88779.
  4. Upgrade to a fixed build. Plan an emergency change window. If you run a high-availability pair, upgrade one node at a time to limit downtime.
  5. If you cannot upgrade today, apply the mitigation. CSO Online reports that Citrix has released Global Deny List signatures as a temporary measure for builds 14.1-73.37 to 73.40 and 13.1-64.23 to 64.27. This is a stopgap, not a fix.
  6. Look for signs of attack. Review logs for unexpected reboots, repeated crashes of the authentication service and login attempts with odd usernames. Keep copies of the logs.
  7. If something looks wrong, escalate. Involve your security team or partner, preserve evidence, and consider resetting sessions and credentials that passed through the appliance.
  8. Fix the process. Three urgent patches in a week is hard for any team. A written patch management process with an emergency path for internet-facing devices makes the next one easier.

Frequently Asked Questions

We do not use SAML on NetScaler. Are we safe?

For CVE-2026-88779, the reported condition is a SAML set-up. However, the two flaws disclosed on 28 September 2026 were rated critical and were also exploited. You should still be on a build that fixes those, and moving to the latest fixed build covers all three.

Our NetScaler is managed by a service provider. What should we ask?

Ask for the current build number of each appliance, the date it was upgraded, whether SAML is configured, and whether logs were checked for signs of attack since late September. Ask for the answers in writing.

Has CERT-In issued an advisory on this?

At the time of writing on 6 October 2026, we have not confirmed a CERT-In advisory specific to CVE-2026-88779. Check the advisories section of the CERT-In website for the latest position, and follow the Citrix bulletin in the meantime.

How Affix Center Can Help

Affix Center is a Mumbai-based IT company that supports organisations with cybersecurity and IT operations, including patch management and monitoring of internet-facing systems. If you need help checking your exposure or setting up a faster patching routine, contact our team.