CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
NetScaler ADC and Gateway SAML memory overflow under active attack

CVE-2026-88779 crashes SAML NetScaler, patch by 7 October

Citrix released emergency builds on 4 October 2026 for CVE-2026-88779, a memory-buffer flaw in customer-managed NetScaler ADC and NetScaler Gateway. Citrix says targeted attacks already caused denial of service on unmitigated appliances that use SAML with Gateway or AAA. CISA added the flaw to the Known Exploited Vulnerabilities catalog the same day and set a federal mitigation date of 7 October.

What happened

The issue is CWE-119, improper restriction of operations inside a memory buffer. Citrix rates it CVSS 8.7. Repeated triggering can keep the service down. Citrix says its analysis so far shows an availability impact and has not identified an effect on customer data integrity. Researchers are still asking whether the same crash path can be pushed further.

Exposure is configuration-dependent. The bulletin applies when the appliance is a Gateway or AAA virtual server and SAML is configured, either as a SAML service provider (authentication samlAction) or as a SAML identity provider (authentication samlIdPProfile). Citrix-managed cloud services, including Gateway Service, are patched by Citrix.

Who is affected

Customer-managed builds in these ranges are in scope when the SAML precondition is met:

  • NetScaler ADC and Gateway 14.1 before 14.1-73.41
  • NetScaler ADC and Gateway 13.1 before 13.1-64.28
  • NetScaler ADC FIPS before 14.1-73.41 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1-37.282

Appliances patched for the earlier September NetScaler issues (CVE-2026-88771 and related) still need this second upgrade if they meet the SAML precondition.

What to do now

Upgrade 14.1 to 14.1-73.41 or later, and 13.1 to 13.1-64.28 or later. FIPS customers should move to 14.1-73.41 FIPS, or 13.1-37.282 on the 13.1 FIPS and NDcPP branch. Check recent unexpected reboots before you call the box clean. Citrix Global Deny List signatures can reduce exposure on a narrow set of recent builds, but they are not a substitute for the fix. Bulletin CTX697174 is the controlling statement.

Source: BleepingComputer, 4 October 2026, citing the Citrix advisory and CISA KEV listing.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Cisco SD-WAN Manager admin bypass is on the KEV list
CVE-2026-76504, no workaround