
CVE-2026-88779: Citrix NetScaler — DoS & Webshell Risk (October 2026)
CVE-2026-88779 — Citrix NetScaler
CVE-2026-88779 is a high-severity vulnerability in Citrix NetScaler ADC and Gateway appliances, allowing attackers to trigger denial of service and deploy webshells on devices configured with SAML authentication. The flaw is under active exploitation, with confirmed incidents at major organizations including Geico. CISA has issued a directive for urgent remediation.
Attack Vector
Attackers exploit CVE-2026-88779 by sending crafted requests to vulnerable NetScaler appliances, causing crashes and forced reboots even after patching. The exploit chain enables execution of malicious scripts and installation of persistent webshells, granting remote access and control. The attacks specifically target appliances with SAML authentication enabled, leveraging the vulnerability to bypass normal controls and maintain access. Security researchers observed malware deployment and ongoing exploitation in the wild.
Who Is at Risk
Citrix NetScaler ADC and Gateway appliances configured with SAML authentication are at immediate risk. Organizations with externally accessible NetScaler devices, especially those not yet patched, are vulnerable. Geico has been confirmed as affected, with multiple other North American enterprises likely targeted. Federal civilian agencies are under CISA remediation orders.
Patch & Mitigate
- Patch: Apply the latest Citrix security updates for NetScaler ADC and Gateway addressing CVE-2026-88779, CVE-2026-88771, and CVE-2026-88772 immediately. CISA mandates federal agencies to patch without delay.
- Workaround: Temporarily disable SAML authentication on affected appliances if patching is not immediately possible.
- Detect: Monitor logs for unexpected appliance reboots, anomalous SAML authentication events, and the presence of unauthorized webshell files or suspicious outbound connections.
MITRE ATT&CK
- TA0005 — Defense Evasion: Attackers use webshells and scripts to maintain persistence and evade detection.
- T1190 — Exploit Public-Facing Application: The vulnerability is exploited via exposed NetScaler interfaces.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

