high Cve 2026 88779 · Exploits

Citrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month's Patch Does Not Cover It

CVSS 8.7 poster: Citrix NetScaler SAML flaw CVE-2026-88779 on CISA KEV
AK

Threat intelligence editor · Published Oct 4, 2026, 9:32 PM EDT

CVE-2026-88779, a SAML-only memory overflow in Citrix NetScaler, is on CISA KEV with a 7 October deadline. September's patch doesn't cover it.

CISA added CVE-2026-88779, a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, to its Known Exploited Vulnerabilities catalog on 4 October 2026 and gave federal agencies until 7 October to act. Only appliances configured as a SAML service provider (SP) or SAML identity provider (IdP) are affected. Citrix describes the impact as denial of service. Ransomware use is listed as "Unknown".

The builds that fixed the September zero-days, CVE-2026-88771 and CVE-2026-88772, do not fix this one. Citrix itself tells customers who upgraded to those builds to upgrade again.

Who is affected

Citrix's bulletin CTX697174, dated 3 October, lists these builds as vulnerable:

Product lineVulnerableFixed in
NetScaler ADC and Gateway 14.1before 14.1-73.4114.1-73.41
NetScaler ADC and Gateway 13.1before 13.1-64.2813.1-64.28
NetScaler ADC 14.1-FIPSbefore 14.1-73.41 FIPS14.1-73.41 FIPS
NetScaler ADC 13.1-FIPS and NDcPPbefore 13.1-37.28213.1-37.282

Secure Private Access Hybrid deployments that use NetScaler instances are also affected. The bulletin covers customer-managed appliances only: Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself. Citrix credits Bishop Fox and watchTowr for the report.

The September fixes, in Citrix bulletin CTX697096 of 27 September, were 14.1-73.37, 14.1-73.37 FIPS, 13.1-64.23 and 13.1-37.279 (our earlier report). Each of those is below the new fixed build. Anyone who stopped at the September release is still vulnerable.

Citrix says so directly. As quoted by BleepingComputer: "If you upgraded your NetScaler deployment with one of the updated software releases identified in the security bulletin for CVE 2026-88771 through CVE 2026-88778, and if you have determined that your NetScaler deployment meets the preconditions describe[d] above, please upgrade your deployment again."

September fixed builds versus the new fixed builds for Citrix NetScaler 14.1, 13.1 and 13.1-FIPS

September's fixed builds on the main lines are all below the builds that fix CVE-2026-88779.

What is known about the flaw

Citrix calls it a memory overflow leading to denial of service and scores it 8.7 under CVSS v4.0, with a network attack vector, low complexity, no privileges and no user interaction. The impact is high on availability only. The weakness is CWE-119. The score comes from Citrix as the CNA. NVD lists it as a secondary score and had not yet analysed the record when we checked, with the status "Received".

Exploitation is confirmed by CISA. Its KEV entry names the flaw as an improper restriction of operations within the bounds of a memory buffer, and the NVD record carries CISA's own assessment of active exploitation, automatable, with partial technical impact. Citrix said in a blog post, quoted by BleepingComputer: "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service." The post adds that the issue "affects service availability, and we have not identified an impact on the integrity of customer data."

How it unfolded

  • Thursday 1 October: NetScaler admins on Reddit reported repeated forced reboots on build 14.1-73.37, per BleepingComputer.
  • Friday 2 October, 19:01 UTC: researcher Kevin Beaumont said his patched 13.1 and 14.1 honeypots were crashing after requests from multiple source IPs (post).
  • Same day: Citrix published a notice about a "newly observed issue" with SAML authentication and said it was separate from the earlier flaws, per BleepingComputer.
  • 3 October: Citrix published bulletin CTX697174.
  • 4 October: the NVD record appeared and CISA added the flaw to KEV.

Is it more than a crash?

Citrix and CISA both describe a denial of service, and we are not claiming code execution. But some evidence points further, and none of it is confirmed:

  • Beaumont reported that one patched honeypot was "running a downloaded (malware) binary" (post).
  • One admin logged crafted SAML usernames carrying shell commands just before the nsaaad process crashed. The admin stressed that the logs showed attempts and correlated crashes, not confirmed execution (BleepingComputer).
  • watchTowr says it reproduced the flaw but has not released details (BleepingComputer).
  • There is precedent. CVE-2025-6543 was also labelled a "memory overflow ... Denial of Service" and was later used for remote code execution, as Beaumont noted (post).

Plan around the documented impact, but treat an exposed SAML appliance as possibly compromised, not only as a denial-of-service risk.

What defenders should do

  1. Check whether you are exposed. Citrix gives two configuration checks. An appliance is in scope if its configuration contains either of these commands:
add authentication samlAction        (appliance acts as a SAML SP)
add authentication samlIdPProfile    (appliance acts as a SAML IdP)
  1. Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS and NDcPP build, even if you patched in September.
  2. Meet the KEV date. Federal agencies must act by 7 October under BOD 26-04. CISA's entry also calls for forensic triage requirements to be followed. (We covered another recent overflow flaw on an edge device in KEV.)
  3. Review exposed appliances as possibly compromised. Treat any SAML-enabled gateway that faced the internet at least since 1 October as a candidate for a compromise check, especially if it was also exposed to the September zero-days.
  4. Know the signs while you schedule the upgrade. Citrix provides Global Deny Lists that block known malicious IP addresses, but still says to install the update. The visible sign is the nsaaad process crashing until the Pitboss supervisor hits its restart limit and reboots the appliance (BleepingComputer). Beaumont published these ns.log patterns to search for: proc nsaaad.*(SIGNALED|EXITED), "maximum number of restarts" and "Pitboss declaring system failure" (post).

Sources

Keep reading

All latest →
  1. criticalExploitsAdobe Commerce and Magento Authorization Flaw CVE-2026-71362 Now Exploited5 min
  2. criticalExploitsShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass5 min
  3. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min
  4. highExploitsMicrosoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE5 min
  5. criticalExploitsWSO2 API Manager JWT Bypass Exploited 133 Days After the Fix5 min
  6. criticalExploitsF5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE6 min