Citrix NetScaler CVE-2026-88779: New SAML Zero-Day, Patch Now
A new NetScaler memory-buffer bug tied to SAML authentication is under active exploitation. Citrix patched it in CTX697174; CISA set an October 7 KEV deadline.

Citrix has shipped an emergency patch for a new NetScaler zero-day, CVE-2026-88779, a memory-buffer vulnerability with a CVSS v4.0 score of 8.7 that affects NetScaler ADC and Gateway appliances configured for SAML authentication. The flaw is under active exploitation, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026, giving federal agencies until October 7, 2026 to patch or disconnect affected systems. If your NetScaler is set up as a SAML service provider or identity provider, treat this as a same-day job.
CVE: CVE-2026-88779 — memory buffer overflow (CWE-119)
CVSS v4.0: 8.7 (High)
Advisory: Citrix CTX697174, published October 3–4, 2026
Trigger condition: NetScaler configured as a SAML Service Provider or SAML Identity Provider
Patched builds: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 FIPS/NDcPP
CISA KEV deadline: October 7, 2026
What is CVE-2026-88779?
CVE-2026-88779 is a memory-buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway, classified under CWE-119 ("Improper Restriction of Operations within the Bounds of a Memory Buffer"). Citrix's own advisory, CTX697174, describes it as a "memory overflow vulnerability leading to Denial of Service," with a CVSS v4.0 base score of 8.7 (vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). In plain terms, an unauthenticated, low-complexity network request can crash the appliance's data plane by overrunning a fixed-size memory buffer during SAML message processing.
The bug only applies to appliances that have SAML authentication turned on. Citrix tells administrators to check their running configuration for either of two command signatures: add authentication samlAction, which configures NetScaler as a SAML Service Provider, or add authentication samlIdPProfile, which configures it as a SAML Identity Provider. If neither entry exists in your configuration, Citrix's advisory indicates your appliance does not meet the precondition for this specific flaw. Citrix credits security researchers at Bishop Fox and watchTowr for reporting the issue.
Citrix's second emergency NetScaler patch in a week
This is Citrix's second out-of-band NetScaler security bulletin in little more than a week. On September 27, 2026, Citrix published CTX697096, disclosing eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778) in the same product line. Two of those — CVE-2026-88771, an unauthenticated command-injection flaw, and CVE-2026-88772, a DTLS-related memory overflow — were already being exploited against unpatched appliances at the time of disclosure, and both were added to CISA's KEV catalog that same day. Our earlier coverage of that September advisory has the full breakdown of those two CVEs and their 14.1-73.37 / 13.1-64.23 fixed builds.
CVE-2026-88779 is a separate, later-discovered issue, patched in newer builds (14.1-73.41 and 13.1-64.28) than the September fix. It is not part of the original eight-CVE batch, and administrators who patched for CTX697096 in late September are not automatically protected against this new flaw — a second, distinct upgrade is required. Two emergency NetScaler bulletins inside eight days is an unusually tight cadence even for a product with NetScaler's recent history of zero-day disclosures, and it reflects how heavily internet-facing VPN and SSO gateways are being targeted by intrusion actors this year.
Who's at risk: SAML service provider and identity provider configurations
SAML (Security Assertion Markup Language) is the XML-based protocol that lets NetScaler sit in the middle of single sign-on flows, either accepting assertions from an external identity provider (acting as a Service Provider) or issuing assertions to downstream applications (acting as an Identity Provider). See Wikipedia's overview of the SAML standard for background on how the assertion exchange works. NetScaler Gateway deployments frequently use SAML to federate remote-access logins with corporate identity providers such as Okta, Entra ID or ADFS, which is why this precondition is common in production VPN and Secure Private Access gateways rather than a niche edge case.
Citrix's advisory specifically flags that Secure Private Access Hybrid deployments that route through customer-managed NetScaler instances are also affected and need the same upgrade; Citrix-managed cloud services are patched centrally by Cloud Software Group and do not require customer action. Everyone else running a self-managed, customer-administered NetScaler ADC or Gateway with either SAML role configured needs to patch their own appliances. That includes organizations that only enabled SAML for a single application or a pilot group of users — the presence of the configuration line is what matters, not how widely it's used in production.
Because SAML processing happens on the NetScaler data plane before a user is authenticated, the precondition check is also a useful reminder of how much trust these appliances carry by design: a device meant to broker identity for everything behind it is, by definition, exposed to the public internet and processing unauthenticated input from anyone who reaches it. That combination is exactly why memory-safety bugs in authentication-adjacent code on edge appliances draw this level of urgency from both vendors and CISA.
Is it being exploited? What we know
CISA's Known Exploited Vulnerabilities catalog is reserved for flaws with reliable evidence of exploitation in the wild, and CVE-2026-88779 was added to that catalog on October 4, 2026 — a day after Citrix's bulletin went live. CISA's own entry classifies the bug by its CWE-119 memory-buffer root cause and requires "forensic triage" under the agency's Binding Operational Directive 26-04, the heightened-response track CISA reserves for edge devices it believes attackers are actively probing or compromising, rather than its standard patch-and-move-on guidance.
Security researchers who have reproduced the bug independently of Citrix describe exploitation attempts hitting the SAML authentication endpoints that the CVE depends on, with scanning traffic probing authentication-related parameters for ways to crash or manipulate the appliance process beyond a simple denial-of-service condition. Citrix's own bulletin text describes the impact strictly as denial-of-service; it does not itself claim remote code execution is possible. Administrators should treat any unexplained NetScaler crash, repeated restart of the nsppe process, or unusual SAML-related log entries since early October as a signal worth investigating, and should preserve logs before rebooting if compromise is suspected, in line with CISA's forensic-triage guidance for KEV-listed edge devices.
It's worth being precise about what is and isn't confirmed here. CISA's KEV entry classifies the vulnerability by its CWE-119 root cause and a "denial of service" impact category, matching Citrix's own description. Neither Citrix's bulletin nor CISA's catalog entry claims remote code execution has been demonstrated for CVE-2026-88779, and this article is not asserting otherwise. What is confirmed, directly from CISA's own criteria for the KEV catalog, is that the agency only lists vulnerabilities after reviewing evidence that exploitation has actually occurred against real deployments — not merely that exploitation is theoretically possible. That bar is why the KEV listing itself, independent of any single researcher's write-up, is the strongest available signal that this is not a theoretical bug.
Timeline: two advisories, eight days apart
| Date | Event |
|---|---|
| September 27, 2026 | Citrix publishes CTX697096, disclosing eight CVEs (CVE-2026-88771 through CVE-2026-88778). CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV the same day. |
| September 28, 2026 | National CERTs, including the Canadian Centre for Cyber Security, issue advisories echoing the September disclosure. |
| October 3, 2026 | Citrix publishes CTX697174, disclosing CVE-2026-88779, a separate memory-buffer flaw tied to SAML configurations, with patched builds 14.1-73.41 / 13.1-64.28. |
| October 4, 2026 | CISA adds CVE-2026-88779 to the KEV catalog, setting a federal remediation due date of October 7, 2026. |
Keeping these two advisories straight matters for patch tracking: they carry different CVE numbers, different CVSS scores, and different fixed builds. A NetScaler running 14.1-73.37 or 13.1-64.23 is protected against the September CVEs but still exposed to CVE-2026-88779 until it's moved to 14.1-73.41 or 13.1-64.28.
Affected and patched NetScaler versions
The table below reflects the version ranges published in Citrix's CTX697174 bulletin. Any build older than the listed patched version is vulnerable if SAML SP or SAML IdP is configured.
| Product line | Affected (before) | Patched version |
|---|---|---|
| NetScaler ADC & Gateway 14.1 | Before 14.1-73.41 | 14.1-73.41 and later |
| NetScaler ADC & Gateway 13.1 | Before 13.1-64.28 | 13.1-64.28 and later |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later |
| NetScaler ADC 13.1-FIPS & NDcPP | Before 13.1-37.282 | 13.1-37.282 and later |
For comparison, the September 27 advisory (CTX697096, CVE-2026-88771/88772) was fixed in the earlier 14.1-73.37 and 13.1-64.23 builds. Appliances sitting on those September builds are not protected against CVE-2026-88779 and still need the newer 14.1-73.41 / 13.1-64.28 releases.
CISA's KEV listing and the October 7 deadline
CISA's Known Exploited Vulnerabilities catalog entry for CVE-2026-88779 sets a remediation due date of October 7, 2026 — three days after it was added. That deadline is binding on U.S. federal civilian executive branch agencies under Binding Operational Directive 26-04, which governs how quickly agencies must act on KEV-listed flaws based on risk. The directive's associated forensic-triage requirement also applies here, meaning agencies running affected NetScaler builds are expected to check for signs of prior compromise, not just install the patch and move on.
Private-sector organizations aren't legally bound by BOD 26-04, but CISA's KEV catalog is widely treated as a de facto patch-priority list across the industry precisely because entries require confirmed exploitation evidence. The National Vulnerability Database's CVE-2026-88779 record carries the same CWE-119 classification and CVSS 8.7 score published by Citrix.
How to check if your NetScaler is vulnerable
Citrix's advisory gives a direct way to self-assess exposure before you even look at version numbers. From the NetScaler CLI or configuration export, search for either of these two command patterns:
add authentication samlAction— indicates the appliance is configured as a SAML Service Provider.add authentication samlIdPProfile— indicates the appliance is configured as a SAML Identity Provider.
If either entry is present in ns.conf and the build is older than the patched versions listed above, the appliance meets Citrix's stated precondition for CVE-2026-88779. Secure Private Access Hybrid environments that proxy through a customer-managed NetScaler should check those instances as well; purely Citrix-managed cloud services are excluded because Cloud Software Group patches them centrally.
Mitigation if you can't patch immediately
Citrix's CTX697174 bulletin lists the version upgrade as the remediation and does not describe a dedicated interim workaround specific to CVE-2026-88779. If an immediate upgrade isn't possible, standard NetScaler hardening still reduces exposure in the meantime: restrict management-plane and VPN-vServer access to known-good IP ranges using NetScaler's responder or rate-limiting policies, and apply IP-level deny lists where SAML-facing vServers are internet-exposed, while you schedule the upgrade. These measures narrow the attack surface but are not a substitute for installing 14.1-73.41 or 13.1-64.28 (or the equivalent FIPS/NDcPP builds) — especially given that CISA has already confirmed exploitation activity against this flaw.
What's next: what NetScaler admins should do now
Three actions, in order. First, identify every customer-managed NetScaler ADC or Gateway instance — including Secure Private Access Hybrid connectors — configured with samlAction or samlIdPProfile, using the self-check commands above. Second, upgrade those appliances to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 FIPS/NDcPP, whichever matches your branch, prioritizing internet-facing SAML Service Provider and Identity Provider gateways first. Third, given CISA's forensic-triage requirement and the active-exploitation evidence behind the KEV listing, review logs for crashes or anomalous SAML authentication traffic predating the patch, and treat any that you find as a potential-compromise investigation rather than a routine crash report.
If you already patched for the September 27 CTX697096 advisory, do not assume you're covered: CVE-2026-88779 requires its own, newer builds. Expect Citrix to keep publishing updates to its security bulletin index as more NetScaler research surfaces; subscribing to Citrix's security-bulletin alerts is the fastest way to catch the next one before attackers do.
Frequently asked questions
What is CVE-2026-88779?
CVE-2026-88779 is a memory-buffer vulnerability (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway with a CVSS v4.0 score of 8.7. It affects appliances configured with SAML authentication, either as a SAML Service Provider or SAML Identity Provider, and Citrix describes it as a memory overflow issue leading to denial of service.
Is CVE-2026-88779 the same as the Citrix NetScaler flaws from September 27, 2026?
No. The September 27, 2026 advisory (CTX697096) covered eight different CVEs, including CVE-2026-88771 and CVE-2026-88772, fixed in builds 14.1-73.37 and 13.1-64.23. CVE-2026-88779 is a separate, later-discovered flaw disclosed on October 3-4, 2026 in advisory CTX697174, fixed in the newer builds 14.1-73.41 and 13.1-64.28.
How do I know if my NetScaler is affected by CVE-2026-88779?
Check your NetScaler configuration for the commands add authentication samlAction (SAML Service Provider) or add authentication samlIdPProfile (SAML Identity Provider). If either is present and your build is older than 14.1-73.41 or 13.1-64.28, your appliance meets Citrix's stated precondition for the vulnerability.
What are the patched NetScaler versions for CVE-2026-88779?
Citrix's advisory CTX697174 lists the fixed builds as NetScaler ADC and Gateway 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 FIPS/NDcPP.
Why did CISA add CVE-2026-88779 to its Known Exploited Vulnerabilities catalog?
CISA only adds vulnerabilities to the KEV catalog when it has reliable evidence of active exploitation. It added CVE-2026-88779 on October 4, 2026, one day after Citrix's bulletin, and set a remediation deadline of October 7, 2026 for federal civilian agencies under Binding Operational Directive 26-04.
Is there a workaround if I can't patch my NetScaler right away?
Citrix's bulletin lists the version upgrade as the remediation and does not describe a dedicated interim workaround for this specific CVE. Restricting access to SAML-facing vServers and management interfaces can reduce exposure temporarily, but it is not a substitute for installing the patched build.
Sources
- Citrix Security Bulletin CTX697174 (CVE-2026-88779)support.citrix.com
- Citrix Security Bulletin CTX697096 (CVE-2026-88771/88772)support.citrix.com
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- CISA Binding Operational Directive 26-04cisa.gov
- NVD: CVE-2026-88779 Detailnvd.nist.gov
- Wikipedia: Security Assertion Markup Language (SAML)en.wikipedia.org
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


