Skip to content
THREATWIRE

CVE

HighActive ExploitationKEV0-day

CVE-2026-88779

NetScaler SAML memory overflow

Memory overflow in customer-managed NetScaler ADC and Gateway when configured as a SAML service provider or identity provider. CISA lists it as exploited. Citrix describes denial of service, not code execution.

CVSS
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Class
DoS
Status
Active Exploitation
KEV
Listed in CISA KEV
0-day
Yes
Vendor
Citrix
Products
NetScaler ADC, NetScaler Gateway
Affected
ADC and Gateway before 14.1-73.41 and before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS and NDcPP before 13.1-37.282. Only when the appliance is a SAML service provider or a SAML identity provider. Citrix-managed cloud services are outside this bulletin.
Fixed
14.1-73.41 and later, 13.1-64.28 and later, 14.1-73.41 FIPS and later, and 13.1-37.282 and later for FIPS and NDcPP.
Published
4 Oct 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-88779 is a memory-buffer flaw in customer-managed Citrix NetScaler ADC and NetScaler Gateway. Citrix bulletin CTX697174 says the appliance is affected when it is configured as a SAML service provider or a SAML identity provider. The vendor rates it 8.7 under CVSS 4.0 and classifies it as CWE-119. The impact Citrix describes is denial of service.

CISA added the CVE to the Known Exploited Vulnerabilities catalog on 4 October 2026. The catalog entry describes a denial of service and does not name a ransomware campaign. Reporting from the same weekend says the flaw was used before the fixed builds were published, so this record is marked 0-day and Active Exploitation.

This is not CVE-2026-88771 or CVE-2026-88772. Those earlier NetScaler issues are fixed in the 14.1-73.37 and 13.1-64.23 line. Installing only those builds does not close CVE-2026-88779.

Citrix has not established remote code execution for this CVE. Separate claims of code execution are not part of this record. The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 for FIPS and NDcPP, and later releases on those branches.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-88779