---
schema: 1
kind: vulnerability
title: "CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)"
headline: "Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not close"
summary: >
  Citrix's bulletin CTX697174 fixes CVE-2026-88779, a memory overflow in NetScaler ADC and Gateway that a network
  attacker needing no privileges reaches when the appliance is configured as a SAML service provider or identity
  provider; Citrix says it has observed targeted attacks and scopes the impact to denial of service. Appliances already
  on the 14.1-73.37 or 13.1-64.23 builds that fixed the September zero-days remain affected and must move to
  14.1-73.41, 13.1-64.28 or the FIPS builds. Reports of code execution on patched honeypots are unconfirmed, and the
  flaw is not in CISA's KEV catalog as of 2026-10-04.
discovered_at: "2026-10-04T04:38:00Z"
updated_at: null
event_date: "2026-10-03"
run_id: 2026-10-04T0405Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, pre-auth, dos, patch-available]
regions: [global]
sectors: []
entities: ["product:citrix-netscaler"]
techniques: [T1190, T1499.004]
affected_products: ["Citrix NetScaler ADC", "Citrix NetScaler Gateway"]
cves:
  - id: CVE-2026-88779
    cvss: "8.7"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "NetScaler ADC and Gateway 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC 14.1-FIPS before 14.1-73.41 FIPS; ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282; only when configured as a SAML service provider or identity provider"
    fixed: "14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282 (13.1-FIPS and 13.1-NDcPP)"
sources:
  - url: "https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-03"
    role: primary
  - url: "https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-03"
    role: primary
  - url: "https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-02"
    role: primary
  - url: "https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products"
    publisher: "ASD's ACSC"
    date: "2026-10-03"
    role: corroborating
  - url: "https://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html"
    publisher: "heise online"
    date: "2026-10-03"
    role: corroborating
  - url: "https://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/"
    publisher: "Cyber Press"
    date: "2026-10-03"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog"
    date: "2026-10-02"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service."
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/"
  - quote: "NetScaler ADC or NetScaler Gateway must be configured as a SAML SP OR SAML IdP"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html"
  - quote: "please upgrade your deployment again with the software released as part of the"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/"
  - quote: "This issue is independent of the vulnerabilities disclosed in"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/"
  - quote: "A remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation."
    publisher: "ASD's ACSC"
    source_url: "https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products"
  - quote: "the watchTowr Labs team has now successfully reproduced this vulnerability."
    publisher: "heise online"
    source_url: "https://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html"
  - quote: "Reports of reboots alone should not be treated as proof of compromise"
    publisher: "Cyber Press"
    source_url: "https://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/"
verification: multi-source
sourcing_note: >
  Citrix scopes the impact to denial of service and says it has not identified an impact on the integrity of customer
  data. The code-execution reading rests on a researcher's honeypot observation and a reproduction claim relayed by
  heise (whose headline asserts code execution), and on ACSC's cautious wording; Citrix does not confirm it. The crash details come
  from administrator reports relayed by Cyber Press, and heise's statement that no patch existed predates the bulletin.
confidence: high
references:
  - "2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev"
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Search every customer-managed NetScaler ADC and Gateway configuration for `add authentication samlAction` or `add authentication samlIdPProfile` and upgrade each match to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, including appliances already on the 14.1-73.37 or 13.1-64.23 builds; where the upgrade has to wait and NetScaler Console virtual patching is available, confirm with `show appfw signatures` that the Global Deny List signature version is at least v24."
  - "Before restarting a SAML-configured NetScaler that has crashed or rebooted repeatedly, preserve its logs and crash artifacts and open a Citrix support case, which Citrix asks for when an appliance is experiencing the impact."
updates: []
migrated_from: null
---

Citrix's bulletin CTX697174 describes CVE-2026-88779, a memory overflow in customer-managed NetScaler ADC and NetScaler Gateway reachable only when the appliance is configured as a SAML service provider or identity provider; the CVSS 4.0 vector is network, no privileges, no interaction, availability impact only ([Citrix, 2026-10-03](https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html)). Citrix says it "has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service" and has not identified an integrity impact on customer data ([Citrix, 2026-10-03](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)). The flaw is independent of the vulnerabilities disclosed in the earlier bulletin CTX697096 ([Citrix, 2026-10-02](https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/)), so an appliance already on 14.1-73.37 or 13.1-64.23 is still affected, and Citrix tells operators who meet the SAML precondition to "upgrade your deployment again" ([Citrix, 2026-10-03](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)). The fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 ([Citrix, 2026-10-03](https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html)).

Until the upgrade, Citrix offers Global Deny List signatures through NetScaler Console with virtual patching enabled, for builds from 14.1-73.37 up to 14.1-73.41 and from 13.1-64.23 up to 13.1-64.28; they "can help to mitigate" the flaw, but the upgrade is the fix ([Citrix, 2026-10-03](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)).

Other reporting reads more into the flaw: administrators reported repeated crashes and reboots of appliances running patched releases, including 14.1-73.37, with the `nsaaad` authentication service failing after crafted SAML-related requests, one seeing a script-download command in the logs that did not succeed and another a payload in the username field ([Cyber Press, 2026-10-03](https://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/)). heise relays researcher Kevin Beaumont's observation that one of two patched honeypots was running a downloaded binary, and a statement that watchTowr Labs reproduced the flaw ([heise online, 2026-10-03](https://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html)); ASD's ACSC says an attacker "may induce system crashes, denial of service and potential exploitation" and that it is aware of impacts to Australian organisations ([ASD's ACSC, 2026-10-03](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products)). None of these sources gives evidence of code execution beyond that observation and reproduction claim, and as of 2026-10-04 the flaw is not in CISA's KEV catalog ([CISA KEV catalog, 2026-10-02](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)).

**Exposure:** a customer-managed NetScaler ADC or Gateway (Secure Private Access Hybrid deployments using NetScaler instances too) whose configuration holds a SAML service-provider or identity-provider action ([Citrix, 2026-10-03](https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html)); Citrix ties the issue to deployments that use SAML authentication with Gateway or AAA virtual servers, and its check is a configuration search for `add authentication samlAction` or `add authentication samlIdPProfile`, then compare the running build with the fixed list above ([Citrix, 2026-10-03](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)).

**Detection:** appliance system, authentication-daemon and HA logs: repeated `nsaaad` crashes, failovers and reboots on a SAML-configured appliance, correlated with inbound SAML request volume in gateway access and firewall logs, since heise says the exploit likely works by sending a massive number of SAML requests ([heise online, 2026-10-03](https://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html)). The Citrix pages list no signs of compromise to look for ([Citrix, 2026-10-03](https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/)), and the crash signs are administrator reports ([Cyber Press, 2026-10-03](https://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/); [heise online, 2026-10-03](https://www.heise.de/en/news/Netscaler-admins-beware-Zero-day-causes-crashes-and-code-execution-11474996.html)).

**Triage:** reboots alone are not proof of compromise; crashes together with malformed authentication traffic and scanning warrant incident-response handling until forensics rules out intrusion ([Cyber Press, 2026-10-03](https://cyberpress.org/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/)).

**Defender takeaway:** treat every SAML-configured NetScaler as exposed even if it is already on the September fixed builds: upgrade to the .41 and .28 builds or the FIPS builds, and use the Global Deny List signatures only as a bridge. Do not read the denial-of-service scoring as a reason to wait: crashes are reported on appliances already on the September builds, and code execution is unconfirmed.
