← Back to CVE intelligence
CVE intelligence

CVE-2026-88779

Citrix NetScaler SAML memory overflow and denial of service

Published Oct 4, 2026Sources checked Oct 4, 2026
8.7HIGHCVSS out of 10
What this means

Exploitation reported: act now

Citrix reports exploitation in the wild. This is separate from CISA KEV membership.

Public exploit: Not collected.

  • Citrix: Citrix reports targeted denial-of-service attacks (2026-10-03)

    Citrix reports targeted attacks on unmitigated SAML deployments that can cause denial of service; repeated triggering can keep service unavailable. Its analysis identifies an availability impact and no identified impact on customer-data integrity. The publication does not establish remote code execution from CVE-2026-88779.

  • Citrix: CTX697174: fixed builds for SAML SP and SAML IdP deployments (2026-10-03)

    Citrix rates CVE-2026-88779 High (CVSS v4.0 8.7, CWE-119). Customer-managed ADC and Gateway builds before 14.1-73.41 or 13.1-64.28, ADC FIPS before 14.1-73.41 FIPS, and ADC FIPS/NDcPP before 13.1-37.282 are affected when configured as a SAML SP or IdP. This includes applicable Secure Private Access Hybrid instances. Citrix manages updates to its cloud services. Install the appropriate fixed build even after the September patches.

What to do next

Remediation and response

  • Upgrade to the fixed build for the deployed branch: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 FIPS/NDcPP. September patches alone do not address this issue.
  • Check both SAML SP and SAML IdP configurations on each customer-managed Gateway or ADC node, including Secure Private Access Hybrid instances.
  • If using Global Deny List while arranging the upgrade, verify the supported build range, Console connectivity, Virtual patching setting and signature version 24 or higher against Citrix guidance.
  • Preserve authentication, crash and network evidence. Treat community-reported payload destinations as hunting leads; Citrix has not attributed them to CVE-2026-88779.
  • Verify the running build and SAML operation on both HA nodes after upgrading. Investigate unexpected execution or persistence separately from the firmware change.

Citrix Security Bulletins guidance

Vendor remediation details

Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible: NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1 NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Vendor-listed releases
  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-88779?

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.