Skip to content
Vulnerability Response

Citrix NetScaler CVE-2026-88779: SAML Memory Overflow DoS Response Guide

4 min read·cyber.encse.com Knowledge Base·Last reviewed 5 Oct 2026

CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer vulnerability (CWE-119) affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP). Citrix has observed targeted attacks against unpatched instances, and successful exploitation causes a denial-of-service condition that can crash the appliance, disrupting the authentication and remote-access services it provides. This is a distinct CVE and mechanism from CVE-2026-88771/CVE-2026-88772 — the unauthenticated command-execution and DTLS memory-overflow RCE pair this site already covers — and affects only deployments using NetScaler's SAML SP/IdP functionality specifically, not every NetScaler instance. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4, 2026, with a federal civilian remediation deadline of October 7, 2026.

A Third NetScaler Zero-Day in Under Two Weeks

This is the third actively-exploited NetScaler CVE added to CISA KEV since September 27, following CVE-2026-88771/88772. Where those two were RCE-class and affected default configurations or DTLS-enabled VPN virtual servers broadly, CVE-2026-88779 is narrower in scope — it only affects appliances configured as a SAML SP or IdP — but the outcome is a crash rather than code execution, which organizations sometimes under-prioritize relative to RCE. A denial-of-service against an authentication gateway is not a minor availability issue: if NetScaler mediates SSO or VPN authentication, a crash can lock out an entire remote workforce until the appliance is restored.

Citrix-managed cloud services and Citrix-managed Adaptive Authentication are not affected — exposure is limited to customer-managed, self-hosted NetScaler ADC/Gateway deployments.

Organizations still cleaning up after CVE-2026-88771/88772 may be tempted to treat this as the same incident reopened. It isn't: separate CVE, separate CWE class (memory buffer bounds versus input validation), and a narrower configuration trigger. Patch tracking for the earlier pair should not be assumed to cover this one.

Determine Exposure

Exposure depends on whether the instance is configured for SAML and its current build version.

  • •Affected: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41, and 13.1 before 13.1-64.28; NetScaler ADC FIPS before 14.1-73.41 FIPS
  • •Confirm whether the instance is configured as a SAML Service Provider or Identity Provider — instances without SAML SP/IdP configuration are not exposed to this specific CVE
  • •If this instance was already patched for CVE-2026-88771/88772 in late September, confirm separately against the 14.1-73.41 / 13.1-64.28 targets above — those are newer fixed builds than the September patch, so remediating the first pair does not close this one
  • •Treat any Gateway/VPN virtual server using SAML for SSO as exposed by default unless the fixed build is confirmed installed

Immediate Response Steps

With confirmed active exploitation and a three-day federal KEV window, treat this as emergency change-control rather than a scheduled maintenance item.

  • •Upgrade to the fixed build — NetScaler ADC/Gateway 14.1-73.41 or 13.1-64.28 or later, or the corresponding FIPS build — as the only complete remediation
  • •While planning the upgrade, apply Citrix's published signatures via the Global Deny List feature to reduce exposure in the interim
  • •Monitor NetScaler appliance stability and logs for unexpected crashes or restarts on SAML-facing virtual servers, which may indicate exploitation attempts
  • •Where SAML SP/IdP functionality is not actually required on a given virtual server, consider disabling it as a compensating control until the upgrade is complete

Pattern Recognition for NetScaler Operators

Three KEV-listed NetScaler CVEs inside two weeks is a signal in itself: organizations running NetScaler as critical SSO/VPN infrastructure should treat the product's current patch cadence as elevated-risk and move to a faster-than-usual update cycle until this cluster of disclosures settles. For India-based organizations where NetScaler mediates remote-access authentication, an appliance-crashing DoS that disrupts VPN or SSO availability for staff should be assessed against CERT-In's six-hour reporting mandate if the outage is attributable to confirmed exploitation rather than routine maintenance — confirm with legal counsel promptly rather than defaulting to 'availability issue, not a breach.'

Need a hand responding to this?

If you’re running an affected version and want help confirming exposure, patching or hunting for compromise, talk to the eNeoteric team.

Contact us

References

Primary sources for the material above. Standards are cited by identifier so they stay findable as publishers reorganise their sites.

  1. Citrix Security Bulletin — NetScaler ADC and NetScaler Gateway SAML Memory Overflow (CVE-2026-88779), 2026-10-04
  2. CISA — Known Exploited Vulnerabilities Catalog, entry added 2026-10-04, due 2026-10-07
  3. CISA Alert — CISA Adds One Known Exploited Vulnerability to Catalog, 2026-10-04