CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)
Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close
Defender actions
- Search every customer-managed NetScaler ADC and Gateway configuration for
add authentication samlActionoradd authentication samlIdPProfileand upgrade each match to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, including appliances already on the 14.1-73.37 or 13.1-64.23 builds; where the upgrade has to wait and NetScaler Console virtual patching is available, confirm withshow appfw signaturesthat the Global Deny List signature version is at least v24. - Before restarting a SAML-configured NetScaler that has crashed or rebooted repeatedly, preserve its logs and crash artifacts and open a Citrix support case, which Citrix asks for when an appliance is experiencing the impact.
Analysis
Citrix's bulletin CTX697174 describes CVE-2026-88779, a memory overflow in customer-managed NetScaler ADC and NetScaler Gateway reachable only when the appliance is configured as a SAML service provider or identity provider; the CVSS 4.0 vector is network, no privileges, no interaction, availability impact only (Citrix, 2026-10-03). Citrix says it "has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service" and has not identified an integrity impact on customer data (Citrix, 2026-10-03). The flaw is independent of the vulnerabilities disclosed in the earlier bulletin CTX697096 (Citrix, 2026-10-02), so an appliance already on 14.1-73.37 or 13.1-64.23 is still affected, and Citrix tells operators who meet the SAML precondition to "upgrade your deployment again" (Citrix, 2026-10-03). The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03).
Until the upgrade, Citrix offers Global Deny List signatures through NetScaler Console with virtual patching enabled, for builds from 14.1-73.37 up to 14.1-73.41 and from 13.1-64.23 up to 13.1-64.28; they "can help to mitigate" the flaw, but the upgrade is the fix (Citrix, 2026-10-03).
Other reporting reads more into the flaw: administrators reported repeated crashes and reboots of appliances running patched releases, including 14.1-73.37, with the nsaaad authentication service failing after crafted SAML-related requests, one seeing a script-download command in the logs that did not succeed and another a payload in the username field (Cyber Press, 2026-10-03). heise relays researcher Kevin Beaumont's observation that one of two patched honeypots was running a downloaded binary, and a statement that watchTowr Labs reproduced the flaw (heise online, 2026-10-03); ASD's ACSC says an attacker "may induce system crashes, denial of service and potential exploitation" and that it is aware of impacts to Australian organisations (ASD's ACSC, 2026-10-03). None of these sources gives evidence of code execution beyond that observation and reproduction claim, and as of 2026-10-04 the flaw is not in CISA's KEV catalog (CISA KEV catalog, 2026-10-02).
Exposure: a customer-managed NetScaler ADC or Gateway (Secure Private Access Hybrid deployments using NetScaler instances too) whose configuration holds a SAML service-provider or identity-provider action (Citrix, 2026-10-03); Citrix ties the issue to deployments that use SAML authentication with Gateway or AAA virtual servers, and its check is a configuration search for add authentication samlAction or add authentication samlIdPProfile, then compare the running build with the fixed list above (Citrix, 2026-10-03).
Triage: reboots alone are not proof of compromise; crashes together with malformed authentication traffic and scanning warrant incident-response handling until forensics rules out intrusion (Cyber Press, 2026-10-03).
Cited evidence
Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP OR SAML IdP
please upgrade your deployment again with the software released as part of the
This issue is independent of the vulnerabilities disclosed in
A remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation.
the watchTowr Labs team has now successfully reproduced this vulnerability.
Reports of reboots alone should not be treated as proof of compromise
Sources7
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.