Last weekend’s NetScaler fire drill got a sequel. Admins who did everything right after PitScaler, patching to 14.1-73.37 inside the KEV window, spent Thursday and Friday watching those same boxes reboot themselves. On Sunday, October 4, Citrix put a number on it: CVE-2026-88779, a memory overflow in NetScaler ADC and Gateway, CVSS 4.0 8.7, exploited in the wild (per Citrix bulletin CTX697174). CISA added it to KEV the same day with an October 7 federal due date.
Who is exposed. Only appliances doing SAML with Gateway or AAA. The check is two config lines: add authentication samlAction (the box is a SAML SP) or add authentication samlIdPProfile (the box is a SAML IdP). If either exists, you’re in scope. Fixed builds: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 for 13.1 FIPS/NDcPP. Secure Private Access hybrid deployments running on NetScaler need the same builds. Citrix-managed cloud gets patched by Citrix.
The uncomfortable part. The PitScaler fix line (14.1-73.37 / 13.1-64.23) is now itself a vulnerable range. BleepingComputer’s timeline: Reddit admins reported forced reboots on 14.1-73.37 on Thursday, including boxes rebuilt from fresh images. nsaaad, the daemon that handles authentication, crashed over and over until Pitboss, NetScaler’s process monitor, hit its restart limit and rebooted the appliance. Citrix posted a notice Friday and shipped fixes early Sunday.
DoS or RCE? Nobody agrees yet. Citrix calls it availability-only and says it hasn’t seen impact on data integrity. watchTowr told SecurityWeek it reproduced the bug, that it only crashes systems, and that it suspects attackers crashed boxes on purpose to speed up exploitation of CVE-2026-88771. Kevin Beaumont says one of his patched honeypots ended up running a downloaded binary. One admin’s logs showed SAML usernames stuffed with shell commands that pulled a payload from 213.209.159[.]55, saved it as /v and ran it, right before three nsaaad crash sequences. That admin was careful to say the logs show attempts, not confirmed execution. Beaumont also noted that CVE-2025-6543 was first written up as a memory-overflow DoS before attacks showed code execution (per BleepingComputer).
Our read: the label matters less than the sequence. A crash that forces a reboot does an attacker favors. It resets state and buries the interesting log lines in noise. Treat a DoS bug sitting in front of your SSO as an exploitation aid until someone proves otherwise.
What we’d do this morning.
1. Inventory. Run show authentication samlAction and show authentication samlIdPProfile on every appliance, including the DR pair nobody logs into.
2. Preserve, then patch. Pull /var/log/ns.log, the nsaaad cores under /var/core, and your syslog copy before you upgrade. Citrix’s IoC script in NetScaler Console can flag “suspicious nobody processes” as a false positive, per watchTowr via Help Net Security, so read the output before you trust it or dismiss it.
3. Hunt. Grep AAA and SAML logs for usernames containing ;, |, backticks, $(, wget or curl. Line those up against nsaaad crashes and Pitboss restarts. Look for outbound connections from the NSIP or SNIP to 213.209.159[.]55, a file at /v, and new PHP or shell files in web paths. The script one admin recovered tries to plant web shells, survive reboots and upload the appliance’s configuration and backups (per SecurityWeek), so check for ns.conf leaving the box.
4. If you find anything, assume secrets are gone. A NetScaler holds LDAP bind accounts, session material and SAML signing keys. Rotate those, not just the firmware.
The buyer angle. SecurityWeek counts this as the sixth exploited NetScaler flaw CISA has added to KEV in 2026. Unit 42 counted 50,277 exposed instances potentially vulnerable to the PitScaler pair as of September 27. That’s the number a CISO should bring to the next renewal. The license is cheap. Patching twice in a week, preserving evidence, and rotating secrets is not. If your remote-access and SSO front door needs an emergency change window every few weeks, that’s a real TCO line, and it belongs in the conversation with Cloud Software Group. It’s also the opening slide for every SSE vendor pitching to retire the VPN concentrator. Take the meeting. Patch first.
