NetScaler CVE-2026-88771 to 88779: Config and Build Check
NetScaler CVE-2026-88779 means some appliances patched on 27 September are vulnerable again. Citrix says anyone who upgraded for the earlier bulletin must upgrade a second time if SAML is configured. The catch is that nine CVEs now sit across two bulletins, and each has its own precondition and fixed build. This guide matches your saved ns.conf and running build against all nine. It rests on reporting that quotes the Citrix bulletins, not on hands-on testing, because the bulletin pages would not load for us.
- Patched on 27 September does not mean safe: CVE-2026-88779 needs 14.1-73.41 or 13.1-64.28.
- Only SAML appliances face CVE-2026-88779, but CVE-2026-88771 reaches every deployment on an affected build.
- CVE-2026-88779 and the two earlier zero-days are all on CISA's exploited list.
- A clean indicator-of-compromise result is not proof, so preserve evidence before you upgrade.
- Citrix-managed cloud services are not affected by CVE-2026-88779, because Citrix patches them itself.
Why NetScaler CVE-2026-88779 hits appliances you already patched
Citrix published bulletin CTX697096 on 27 September. It fixed eight flaws, CVE-2026-88771 through 88778, and confirmed that two were already exploited. The fixed builds were 14.1-73.37 and 13.1-64.23.
How the timeline unfolded
Then the crashes started. Field Effect says reports of repeated crashes surfaced on 1 October, before the new flaw was public. BleepingComputer’s corrected timeline says Friday 2 October, so the exact day is unsettled. Administrators described forced reboots on appliances running 14.1-73.37, including rebuilt ones. The nsaaad authentication service kept crashing until Pitboss hit its restart limit and rebooted the box.
Citrix answered on 3 October with bulletin CTX697174. It covers CVE-2026-88779, a memory overflow in SAML processing with a CVSS v4 score of 8.7. CISA added it to its exploited list on 4 October and gave federal agencies until 7 October to act. Some outlets date the disclosure 4 October, but watchTowr and Field Effect give 3 October for the bulletin itself.
Denial of service or code execution?
Citrix calls it a denial-of-service flaw and says it found no impact on customer data integrity. Researchers are less sure. BleepingComputer relays logs showing crafted usernames that carried shell commands. Kevin Beaumont also found a downloaded binary running on a patched honeypot. Yet Help Net Security says it is still unclear whether the flaw can lead to remote code execution.
The Register adds that watchTowr suspects attackers use the crashes to speed up exploitation of CVE-2026-88771. That is a suspicion, not a finding, so we treat the impact as open.
The nine CVEs and the config each one needs
Citrix defines each precondition, and the table below keeps to that wording. All scores are CVSS v4. Only CVE-2026-88771 applies to every deployment on an affected build, while the rest depend on what sits in your configuration.
| CVE-2026-88771 | 9.5, exploited. Unauthenticated command execution. Every deployment, default config. |
|---|---|
| CVE-2026-88772 | 9.5, exploited. Remote code execution or DoS. DTLS enabled, which is the default on VPN vservers. |
| CVE-2026-88773 | 9.3. HTTP request smuggling. LB, CS, VPN or authentication vservers of type HTTP or SSL. |
| CVE-2026-88774 | 7.0. Policy bypass. Any policy using an HTTP URL-based expression. |
| CVE-2026-88775 | 8.8. Memory overflow, DoS. Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver. |
| CVE-2026-88776 | 8.8. Memory overflow, DoS. Load balancing vservers of type Oracle. |
| CVE-2026-88777 | 8.8. Memory overflow, DoS. LB, CS or CGNAT-LSN/NAT64 with a non-HTTP Layer 7 feature such as FTP, RTSP or DNS64. |
| CVE-2026-88778 | 8.8. TCP ISN prediction. TCP-based vservers (HTTP, SSL, TCP) with Enhanced ISN Generation disabled. |
| CVE-2026-88779 | 8.7, exploited. Memory overflow, DoS. SAML SP or IdP in use with Gateway or AAA. |
Citrix’s bulletin does not list the other six as exploited. According to watchTowr, CISA has listed CVE-2026-88771 and 88772 since 27 September. CVE-2026-88779 followed on 4 October.
Fixed builds by branch
A second bulletin moved the floor. Compare your running build with both columns, because an appliance can pass the first and still fail the second.
| Branch | 88771 to 88778 (CTX697096) | 88779 (CTX697174) |
|---|---|---|
| 14.1 | 14.1-73.37 | 14.1-73.41 |
| 13.1 | 13.1-64.23 | 13.1-64.28 |
| 14.1 FIPS | 14.1-73.37 FIPS | 14.1-73.41 FIPS |
| 13.1 FIPS and NDcPP | 13.1-37.279 | 13.1-37.282 |
The Hacker News reports that 13.1 reached End of Maintenance on 15 September, yet Citrix still shipped 13.1 fixes. That alone is a reason to schedule the move to 14.1.
Which build do you need? A short decision path

Start with SAML. If your config has no samlAction or samlIdPProfile entry, CVE-2026-88779 does not apply. Then check the build against the first column for the other eight. If SAML is present and you run below the newer floor, upgrade again, even if you patched on 27 September.
If you cannot upgrade today, the Global Deny List signatures are a stopgap. We found nothing confirming that the newer builds carry every earlier fix, so check that in the bulletin before you choose a target.
How to check your appliance against the matrix
You need two inputs: a saved copy of ns.conf and the running build. Read them offline, so nothing touches the live appliance. NetScaler Console offers a second route, because its security advisory dashboard lists impacted instances for CVE-2026-88779 after a version scan.
Step 1: Save the config and note the build
Copy the saved configuration to a workstation, then note the running build from the appliance or from NetScaler Console. Do this for every node. One response guide advises checking both HA peers and any recovery instances.
Step 2: Check SAML for CVE-2026-88779
Search for the two entries Citrix names: grep -E '^add authentication (samlAction|samlIdPProfile)' ns.conf.
A samlAction entry means a SAML service provider. A samlIdPProfile entry means an identity provider. Either one meets the precondition when the appliance also uses Gateway or AAA functionality.
Step 3: Check DTLS for CVE-2026-88772
Citrix says DTLS is on by default for VPN virtual servers. So list them with grep -E '^add vpn vserver' ns.conf and look for an explicit -dtls OFF. A VPN vserver without it is exposed on an affected build. The same response guide also says to look for virtual servers of type DTLS.
Step 4: Check the other preconditions
For CVE-2026-88773, run grep -Ei '^add (lb|cs|vpn|authentication) vserver \S+ (HTTP|SSL)' ns.conf. For CVE-2026-88776, run grep -Ei '^add lb vserver \S+ ORACLE' ns.conf. Swap ORACLE for FTP or RTSP to start on CVE-2026-88777.
For CVE-2026-88774, search policies for HTTP.REQ.URL. For CVE-2026-88778, run show ns tcpParam on the live appliance, because a setting left at its default may not show up in the file.
Step 5: Compare the build with the fixed table
A 14.1 appliance below 14.1-73.41 needs the upgrade if SAML is present. A 13.1 appliance below 13.1-64.28 does too. FIPS and NDcPP appliances use their own floors. In NetScaler Console, remediation for CVE-2026-88779 is a single-step upgrade workflow for the impacted instances.
Reading the result: three illustrative cases
These cases are illustrations, not reports from real appliances. A 14.1-73.37 appliance with a samlAction entry and a Gateway vserver meets the CVE-2026-88779 precondition. It sits below 14.1-73.41, so it needs the second upgrade.
A 13.1-64.23 appliance with no SAML entries meets the first column, and Citrix’s instruction to upgrade again does not apply to it. A 14.1-73.32 appliance, the build that fixed an exploited bypass in August, is below both floors. It needs the upgrade even without SAML, because CVE-2026-88771 applies to every deployment.
Compromise checks before and after the upgrade
Preserve evidence first. Citrix’s guidance for a suspected compromise lists a VPX snapshot, remote syslog data, a support bundle and a packet-engine core dump, as relayed by The Hacker News. watchTowr’s FAQ uses the same order for this flaw: preserve, check the config, run the indicator-of-compromise script, then upgrade.
Then look for the crash pattern. Field Effect points to repeated nsaaad crashes, Pitboss restart events, unexpected reboots and repeated requests aimed at SAML services. One administrator’s logs, relayed by BleepingComputer, show crafted usernames that fetched a payload from 213.209.159[.]55. Those logs showed attempts, not confirmed execution.
What stands out to me is how little a patch proves here. Two of these flaws were exploited before any fix existed, so the upgrade closes the door but says nothing about who already walked through. If you confirm a compromise, watchTowr’s FAQ says to deploy a new instance rather than reuse the appliance.
Citrix’s guidance also covers isolating the appliance, changing secrets stored on it, resetting passwords of users who signed in through it, and revoking its certificates and keys. The Dutch NCSC’s 2025 check scripts are another option, but the live-appliance script’s README says it is not specific to one vulnerability and carries no guarantee.
Interim mitigations and what is still unverified
Citrix pushed Global Deny List signatures that block known malicious IP addresses. They are a stopgap, not a fix, and watchTowr says they cover specific intermediate builds with Virtual patching enabled in NetScaler Console. An attacker on a new address would not be blocked, so schedule the upgrade.
Four points remain open. We could not confirm whether CVE-2026-88779 allows code execution, since watchTowr has not published details. Nothing we read says whether the newer builds carry every earlier fix. Rollback is also unverified: NetScaler documents downgrade procedures for standalone and HA setups, but we did not check them against these builds. And Citrix’s own bulletin and blog pages returned errors, so every Citrix claim here comes from outlets quoting them.
Frequently Asked Questions
01 Do I need to upgrade again after patching on 27 September?
02 Is CVE-2026-88779 only a denial-of-service flaw?
03 Does the Global Deny List replace the upgrade?
04 How do I find which appliances are affected?
Verdict: who should upgrade first
Upgrade SAML-enabled appliances first, starting with any that face the internet. Field Effect notes that exploitation needs no credentials and no user interaction. Next come appliances with VPN vservers and DTLS, then everything else below the fixed builds, because CVE-2026-88771 reaches all of them.
This checklist is the wrong tool in two cases. If you run only Citrix-managed cloud services or Adaptive Authentication, Citrix applies the updates for you. And if you already suspect a compromise, follow Citrix’s guidance and call incident response instead of relying on a config check. Last verified 8 October 2026. Recheck after any change to bulletin CTX697174, or once researchers publish details of CVE-2026-88779.
