CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Citrix NetScaler ADC and Gateway, SAML-triggered memory overflow (CVSS 4.0 8.7), targeted attacks confirmed by Citrix; the September fixed builds do not cover it

cve · CVE-2026-88779

Coverage
1
first 2026-10-04 → last 2026-10-04
Latest activity
2026-10-04
Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close
Peak priority
high
1 high
Targets
·
no sector or region stated
Sources cited
7
6 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-88779, newest first. Check the date before acting on an older one.

  • Search every customer-managed NetScaler ADC and Gateway configuration for add authentication samlAction or add authentication samlIdPProfile and upgrade each match to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, including appliances already on the 14.1-73.37 or 13.1-64.23 builds; where the upgrade has to wait and NetScaler Console virtual patching is available, confirm with show appfw signatures that the Global Deny List signature version is at least v24.
    2026-10-04CVE-2026-88779
  • Before restarting a SAML-configured NetScaler that has crashed or rebooted repeatedly, preserve its logs and crash artifacts and open a Citrix support case, which Citrix asks for when an appliance is experiencing the impact.
    2026-10-04CVE-2026-88779

Defender insights

What each entry about CVE-2026-88779 tells a defender to do, newest first.

2026-10-04HIGHexploitedCitrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close

Triage · detection

Story timeline

  1. 2026-10-04CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)
    trending-vulnerabilitiesCitrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ImpactEndpoint Denial of Service: Application or System Exploitation

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited · ATT&CK page ↗

Impact TA0040

T1499.004Endpoint Denial of Service: Application or System Exploitation×1

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.

Evidence: 2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited · ATT&CK page ↗

Entries about Citrix NetScaler ADC and Gateway, SAML-triggered memory overflow (CVSS 4.0 8.7), targeted attacks confirmed by Citrix; the September fixed builds do not cover it (1)

2026-10-04 · view entry permalink →

HIGHCVE-2026-88779exploitedNATOA2

CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)

Citrix's bulletin CTX697174 describes CVE-2026-88779, a memory overflow in customer-managed NetScaler ADC and NetScaler Gateway reachable only when the appliance is configured as a SAML service provider or identity provider; the CVSS 4.0 vector is network, no privileges, no interaction, availability impact only (Citrix, 2026-10-03). Citrix says it "has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service" and has not identified an integrity impact on customer data (Citrix, 2026-10-03). The flaw is independent of the vulnerabilities disclosed in the earlier bulletin CTX697096 (Citrix, 2026-10-02), so an appliance already on 14.1-73.37 or 13.1-64.23 is still affected, and Citrix tells operators who meet the SAML precondition to "upgrade your deployment again" (Citrix, 2026-10-03). The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03).

Until the upgrade, Citrix offers Global Deny List signatures through NetScaler Console with virtual patching enabled, for builds from 14.1-73.37 up to 14.1-73.41 and from 13.1-64.23 up to 13.1-64.28; they "can help to mitigate" the flaw, but the upgrade is the fix (Citrix, 2026-10-03).

Other reporting reads more into the flaw: administrators reported repeated crashes and reboots of appliances running patched releases, including 14.1-73.37, with the nsaaad authentication service failing after crafted SAML-related requests, one seeing a script-download command in the logs that did not succeed and another a payload in the username field (Cyber Press, 2026-10-03). heise relays researcher Kevin Beaumont's observation that one of two patched honeypots was running a downloaded binary, and a statement that watchTowr Labs reproduced the flaw (heise online, 2026-10-03); ASD's ACSC says an attacker "may induce system crashes, denial of service and potential exploitation" and that it is aware of impacts to Australian organisations (ASD's ACSC, 2026-10-03). None of these sources gives evidence of code execution beyond that observation and reproduction claim, and as of 2026-10-04 the flaw is not in CISA's KEV catalog (CISA KEV catalog, 2026-10-02).

Exposure: a customer-managed NetScaler ADC or Gateway (Secure Private Access Hybrid deployments using NetScaler instances too) whose configuration holds a SAML service-provider or identity-provider action (Citrix, 2026-10-03); Citrix ties the issue to deployments that use SAML authentication with Gateway or AAA virtual servers, and its check is a configuration search for add authentication samlAction or add authentication samlIdPProfile, then compare the running build with the fixed list above (Citrix, 2026-10-03).

Triage: reboots alone are not proof of compromise; crashes together with malformed authentication traffic and scanning warrant incident-response handling until forensics rules out intrusion (Cyber Press, 2026-10-03).

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP OR SAML IdP

please upgrade your deployment again with the software released as part of the

This issue is independent of the vulnerabilities disclosed in

Citrix (Cloud Software Group) 2026-10-03

A remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation.

ASD's ACSC 2026-10-03

the watchTowr Labs team has now successfully reproduced this vulnerability.

heise online 2026-10-03

Reports of reboots alone should not be treated as proof of compromise

Cyber Press 2026-10-03

Builds on: Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA…

vulnerability04 Oct 04:38Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • community.citrix.com2 (29%)
  • cisa.gov1 (14%)
  • cyber.gov.au1 (14%)
  • cyberpress.org1 (14%)
  • heise.de1 (14%)
  • support.citrix.com1 (14%)