2026-10-04HIGHexploitedCitrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close
Citrix NetScaler ADC and Gateway, SAML-triggered memory overflow (CVSS 4.0 8.7), targeted attacks confirmed by Citrix; the September fixed builds do not cover it
cve · CVE-2026-88779
Coverage
1
first 2026-10-04 → last 2026-10-04
Latest activity
2026-10-04
Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close
Peak priority
high
1 high
Targets
·
no sector or region stated
Sources cited
7
6 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-88779, newest first. Check the date before acting on an older one.
- Search every customer-managed NetScaler ADC and Gateway configuration for2026-10-04CVE-2026-88779
add authentication samlActionoradd authentication samlIdPProfileand upgrade each match to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, including appliances already on the 14.1-73.37 or 13.1-64.23 builds; where the upgrade has to wait and NetScaler Console virtual patching is available, confirm withshow appfw signaturesthat the Global Deny List signature version is at least v24. - Before restarting a SAML-configured NetScaler that has crashed or rebooted repeatedly, preserve its logs and crash artifacts and open a Citrix support case, which Citrix asks for when an appliance is experiencing the impact.2026-10-04CVE-2026-88779
Defender insights
What each entry about CVE-2026-88779 tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ImpactEndpoint Denial of Service: Application or System Exploitation
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited · ATT&CK page ↗
Impact TA0040
T1499.004Endpoint Denial of Service: Application or System Exploitation×1
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.
Evidence: 2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited · ATT&CK page ↗
Entries about Citrix NetScaler ADC and Gateway, SAML-triggered memory overflow (CVSS 4.0 8.7), targeted attacks confirmed by Citrix; the September fixed builds do not cover it (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- community.citrix.com2 (29%)
- cisa.gov1 (14%)
- cyber.gov.au1 (14%)
- cyberpress.org1 (14%)
- heise.de1 (14%)
- support.citrix.com1 (14%)
External references
All cited sources (7)
- support.citrix.comprimaryCitrix (Cloud Software Group)https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- community.citrix.comCitrix (Cloud Software Group)https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
- community.citrix.comCitrix (Cloud Software Group)https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
- cyber.gov.auASD's ACSChttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
- cyberpress.orgCyber Presshttps://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/
- heise.deheise onlinehttps://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html