What Happened
Citrix released emergency fixes on October 4 for the NetScaler SAML zero-day CVE-2026-88779. BleepingComputer reports a memory overflow in NetScaler ADC and Gateway with a CVSS score of 8.7. Citrix classifies it as a denial-of-service flaw and confirms targeted attacks on unmitigated systems. Researchers saw more. Attackers sent crafted usernames carrying shell commands and pulled payloads from a remote server, which points toward code execution.
The Hacker News credits Bishop Fox and watchTowr with the discovery. watchTowr reproduced the bug within hours of spotting honeypot activity. Only appliances configured as a SAML service provider or identity provider are exposed. Fixed builds are 14.1-73.41 and 13.1-64.28, plus matching FIPS releases. CISA added the flaw to its Known Exploited Vulnerabilities catalog with an October 7 deadline.
Why This Matters for Canadian Organizations
NetScaler sits at the edge of Canadian banks, hospitals, universities, and government departments. It handles remote access and single sign-on for staff. A SAML outage there locks out every user who authenticates through the appliance. Attackers who turn the overflow into code execution gain a foothold inside the perimeter.
This is the second NetScaler zero-day campaign in a week. Teams with the late-September flaws behind them are not finished. Canadian federal departments treat CISA deadlines as a working benchmark, and provincial and municipal operators with the same appliances should adopt October 7 as their own. An outage at an identity gateway also raises incident reporting questions for federally regulated financial institutions under OSFI expectations.
What to Do
Search your NetScaler configuration for authentication samlAction and authentication samlIdPProfile entries. Upgrade to 14.1-73.41 or 13.1-64.28 or later. Review authentication logs for usernames containing shell syntax. Hunt for outbound traffic to 213.209.159[.]55. Confirm last week’s patches are still in place. Follow our TechTalk coverage and our daily briefs for updates.






