Citrix released emergency builds on 4 October 2026 for CVE-2026-88779, a memory-buffer flaw in customer-managed NetScaler ADC and NetScaler Gateway. Citrix says targeted attacks already caused denial of service on unmitigated appliances that use SAML with Gateway or AAA. CISA added the flaw to the Known Exploited Vulnerabilities catalog the same day and set a federal mitigation date of 7 October.
What happened
The issue is CWE-119, improper restriction of operations inside a memory buffer. Citrix rates it CVSS 8.7. Repeated triggering can keep the service down. Citrix says its analysis so far shows an availability impact and has not identified an effect on customer data integrity. Researchers are still asking whether the same crash path can be pushed further.
Exposure is configuration-dependent. The bulletin applies when the appliance is a Gateway or AAA virtual server and SAML is configured, either as a SAML service provider (authentication samlAction) or as a SAML identity provider (authentication samlIdPProfile). Citrix-managed cloud services, including Gateway Service, are patched by Citrix.
Who is affected
Customer-managed builds in these ranges are in scope when the SAML precondition is met:
- NetScaler ADC and Gateway 14.1 before 14.1-73.41
- NetScaler ADC and Gateway 13.1 before 13.1-64.28
- NetScaler ADC FIPS before 14.1-73.41 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.282
Appliances patched for the earlier September NetScaler issues (CVE-2026-88771 and related) still need this second upgrade if they meet the SAML precondition.
What to do now
Upgrade 14.1 to 14.1-73.41 or later, and 13.1 to 13.1-64.28 or later. FIPS customers should move to 14.1-73.41 FIPS, or 13.1-37.282 on the 13.1 FIPS and NDcPP branch. Check recent unexpected reboots before you call the box clean. Citrix Global Deny List signatures can reduce exposure on a narrow set of recent builds, but they are not a substitute for the fix. Bulletin CTX697174 is the controlling statement.
Source: BleepingComputer, 4 October 2026, citing the Citrix advisory and CISA KEV listing.
Also on the blog
- CVE-2026-105207 ZITADEL account takeover, upgrade to 4.17.3
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- TA419 phishes AI policy experts with Microsoft AitM
- ShinyHunters suspect Rey detained in Jordan, sources say
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.