Skip to content
THREATWIRE

Threats

NetScaler SAML memory overflow is being exploited

CVE-2026-88779 is in the CISA KEV catalog. Citrix limits it to SAML service-provider or identity-provider configurations and describes denial of service. Earlier NetScaler fixes do not close it.

High

Published 5 Oct 2026 · Updated 5 Oct 2026

What happened

CVE-2026-88779 is a memory overflow in customer-managed Citrix NetScaler ADC and NetScaler Gateway. Citrix bulletin CTX697174 scores it 8.7 on CVSS 4.0 and classifies it as CWE-119, improper restriction of operations inside a memory buffer. The published outcome is denial of service: the appliance can be taken offline.

CISA added the CVE to the Known Exploited Vulnerabilities catalog on 4 October 2026, in a one-item alert the same day. The catalog entry tells federal civilian agencies to follow BOD 26-04 and sets a remediation date of 7 October 2026. Known ransomware use is listed as unknown. Citrix had already described exploitation against unpatched deployments, which is why the ThreatWire record is Active Exploitation and a 0-day: use was reported before the Sunday builds that close it.

Who is affected

The precondition is a configuration, not every NetScaler on the network. The appliance has to be a SAML service provider or a SAML identity provider. Citrix tells customers to look for add authentication samlAction or add authentication samlIdPProfile. Secure Private Access hybrid deployments that use those NetScaler instances are in scope as well.

Citrix-managed cloud services and Citrix-managed Adaptive Authentication are outside this bulletin. Cloud Software Group updates those itself. An appliance that is not configured as a SAML service provider or identity provider is not the affected case.

Supported branches before the fix are 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, 14.1 FIPS before 14.1-73.41 FIPS, and 13.1 FIPS and NDcPP before 13.1-37.282.

What is confirmed

CISA’s catalog and the Citrix bulletin both describe denial of service. The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282, plus later releases on those branches. The bulletin does not list a configuration workaround that replaces the upgrade.

CVE-2026-88771 and CVE-2026-88772 are different NetScaler bugs. They were fixed earlier, in 14.1-73.37 and 13.1-64.23. Those updates do not close 88779.

What is not confirmed

Reporting around the crashes has asked whether the same bug can be used for code execution. That question is not a finding. Citrix and CISA have published denial of service, not remote code execution. The ThreatWire record stays a denial-of-service issue. It is not a stand-in for 88771 or 88772.

What to do

Customer-managed appliances that match the SAML precondition should move to one of the fixed builds above. Federal civilian agencies on the public internet side of BOD 26-04 are on the 7 October 2026 date in the KEV entry. After the upgrade, the useful check is whether the appliance was exposed before the patch, which is the triage CISA points to in that directive.

Sources: Citrix bulletin CTX697174, the CISA KEV catalog entry for CVE-2026-88779, the CISA alert of 4 October 2026, and NVD.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/threats/netscaler-saml-memory-overflow-is-being-exploited