CVE-2026-88779
NetScaler SAML memory overflow
Memory overflow in customer-managed NetScaler ADC and Gateway when configured as a SAML service provider or identity provider. CISA lists it as exploited. Citrix describes denial of service, not code execution.
- CVSS
- 8.7
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Class
- DoS
- Status
- Active Exploitation
- KEV
- Listed in CISA KEV
- 0-day
- Yes
- Vendor
- Citrix
- Products
- NetScaler ADC, NetScaler Gateway
- Affected
- ADC and Gateway before 14.1-73.41 and before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS and NDcPP before 13.1-37.282. Only when the appliance is a SAML service provider or a SAML identity provider. Citrix-managed cloud services are outside this bulletin.
- Fixed
- 14.1-73.41 and later, 13.1-64.28 and later, 14.1-73.41 FIPS and later, and 13.1-37.282 and later for FIPS and NDcPP.
- CWE
- CWE-119
- Published
- 4 Oct 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-88779 is a memory-buffer flaw in customer-managed Citrix NetScaler ADC and NetScaler Gateway. Citrix bulletin CTX697174 says the appliance is affected when it is configured as a SAML service provider or a SAML identity provider. The vendor rates it 8.7 under CVSS 4.0 and classifies it as CWE-119. The impact Citrix describes is denial of service.
CISA added the CVE to the Known Exploited Vulnerabilities catalog on 4 October 2026. The catalog entry describes a denial of service and does not name a ransomware campaign. Reporting from the same weekend says the flaw was used before the fixed builds were published, so this record is marked 0-day and Active Exploitation.
This is not CVE-2026-88771 or CVE-2026-88772. Those earlier NetScaler issues are fixed in the 14.1-73.37 and 13.1-64.23 line. Installing only those builds does not close CVE-2026-88779.
Citrix has not established remote code execution for this CVE. Separate claims of code execution are not part of this record. The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 for FIPS and NDcPP, and later releases on those branches.