CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
HIGHCVE-2026-88779exploitedNATOA2vulnerability

CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)

Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close

Defender actions

  • Search every customer-managed NetScaler ADC and Gateway configuration for add authentication samlAction or add authentication samlIdPProfile and upgrade each match to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, including appliances already on the 14.1-73.37 or 13.1-64.23 builds; where the upgrade has to wait and NetScaler Console virtual patching is available, confirm with show appfw signatures that the Global Deny List signature version is at least v24.
  • Before restarting a SAML-configured NetScaler that has crashed or rebooted repeatedly, preserve its logs and crash artifacts and open a Citrix support case, which Citrix asks for when an appliance is experiencing the impact.

Analysis

Citrix's bulletin CTX697174 describes CVE-2026-88779, a memory overflow in customer-managed NetScaler ADC and NetScaler Gateway reachable only when the appliance is configured as a SAML service provider or identity provider; the CVSS 4.0 vector is network, no privileges, no interaction, availability impact only (Citrix, 2026-10-03). Citrix says it "has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service" and has not identified an integrity impact on customer data (Citrix, 2026-10-03). The flaw is independent of the vulnerabilities disclosed in the earlier bulletin CTX697096 (Citrix, 2026-10-02), so an appliance already on 14.1-73.37 or 13.1-64.23 is still affected, and Citrix tells operators who meet the SAML precondition to "upgrade your deployment again" (Citrix, 2026-10-03). The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03).

Until the upgrade, Citrix offers Global Deny List signatures through NetScaler Console with virtual patching enabled, for builds from 14.1-73.37 up to 14.1-73.41 and from 13.1-64.23 up to 13.1-64.28; they "can help to mitigate" the flaw, but the upgrade is the fix (Citrix, 2026-10-03).

Other reporting reads more into the flaw: administrators reported repeated crashes and reboots of appliances running patched releases, including 14.1-73.37, with the nsaaad authentication service failing after crafted SAML-related requests, one seeing a script-download command in the logs that did not succeed and another a payload in the username field (Cyber Press, 2026-10-03). heise relays researcher Kevin Beaumont's observation that one of two patched honeypots was running a downloaded binary, and a statement that watchTowr Labs reproduced the flaw (heise online, 2026-10-03); ASD's ACSC says an attacker "may induce system crashes, denial of service and potential exploitation" and that it is aware of impacts to Australian organisations (ASD's ACSC, 2026-10-03). None of these sources gives evidence of code execution beyond that observation and reproduction claim, and as of 2026-10-04 the flaw is not in CISA's KEV catalog (CISA KEV catalog, 2026-10-02).

Exposure: a customer-managed NetScaler ADC or Gateway (Secure Private Access Hybrid deployments using NetScaler instances too) whose configuration holds a SAML service-provider or identity-provider action (Citrix, 2026-10-03); Citrix ties the issue to deployments that use SAML authentication with Gateway or AAA virtual servers, and its check is a configuration search for add authentication samlAction or add authentication samlIdPProfile, then compare the running build with the fixed list above (Citrix, 2026-10-03).

Triage: reboots alone are not proof of compromise; crashes together with malformed authentication traffic and scanning warrant incident-response handling until forensics rules out intrusion (Cyber Press, 2026-10-03).

Cited evidence

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP OR SAML IdP

please upgrade your deployment again with the software released as part of the

This issue is independent of the vulnerabilities disclosed in

Citrix (Cloud Software Group) 2026-10-03

A remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation.

ASD's ACSC 2026-10-03

the watchTowr Labs team has now successfully reproduced this vulnerability.

heise online 2026-10-03

Reports of reboots alone should not be treated as proof of compromise

Cyber Press 2026-10-03

Sources7

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.