CVE-2026-88779, a SAML-only memory overflow in Citrix NetScaler, is on CISA KEV with a 7 October deadline. September's patch doesn't cover it.
CISA added CVE-2026-88779, a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, to its Known Exploited Vulnerabilities catalog on 4 October 2026 and gave federal agencies until 7 October to act. Only appliances configured as a SAML service provider (SP) or SAML identity provider (IdP) are affected. Citrix describes the impact as denial of service. Ransomware use is listed as "Unknown".
The builds that fixed the September zero-days, CVE-2026-88771 and CVE-2026-88772, do not fix this one. Citrix itself tells customers who upgraded to those builds to upgrade again.
Who is affected
Citrix's bulletin CTX697174, dated 3 October, lists these builds as vulnerable:
| Product line | Vulnerable | Fixed in |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | before 14.1-73.41 | 14.1-73.41 |
| NetScaler ADC and Gateway 13.1 | before 13.1-64.28 | 13.1-64.28 |
| NetScaler ADC 14.1-FIPS | before 14.1-73.41 FIPS | 14.1-73.41 FIPS |
| NetScaler ADC 13.1-FIPS and NDcPP | before 13.1-37.282 | 13.1-37.282 |
Secure Private Access Hybrid deployments that use NetScaler instances are also affected. The bulletin covers customer-managed appliances only: Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself. Citrix credits Bishop Fox and watchTowr for the report.
The September fixes, in Citrix bulletin CTX697096 of 27 September, were 14.1-73.37, 14.1-73.37 FIPS, 13.1-64.23 and 13.1-37.279 (our earlier report). Each of those is below the new fixed build. Anyone who stopped at the September release is still vulnerable.
Citrix says so directly. As quoted by BleepingComputer: "If you upgraded your NetScaler deployment with one of the updated software releases identified in the security bulletin for CVE 2026-88771 through CVE 2026-88778, and if you have determined that your NetScaler deployment meets the preconditions describe[d] above, please upgrade your deployment again."
September's fixed builds on the main lines are all below the builds that fix CVE-2026-88779.
What is known about the flaw
Citrix calls it a memory overflow leading to denial of service and scores it 8.7 under CVSS v4.0, with a network attack vector, low complexity, no privileges and no user interaction. The impact is high on availability only. The weakness is CWE-119. The score comes from Citrix as the CNA. NVD lists it as a secondary score and had not yet analysed the record when we checked, with the status "Received".
Exploitation is confirmed by CISA. Its KEV entry names the flaw as an improper restriction of operations within the bounds of a memory buffer, and the NVD record carries CISA's own assessment of active exploitation, automatable, with partial technical impact. Citrix said in a blog post, quoted by BleepingComputer: "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service." The post adds that the issue "affects service availability, and we have not identified an impact on the integrity of customer data."
How it unfolded
- Thursday 1 October: NetScaler admins on Reddit reported repeated forced reboots on build 14.1-73.37, per BleepingComputer.
- Friday 2 October, 19:01 UTC: researcher Kevin Beaumont said his patched 13.1 and 14.1 honeypots were crashing after requests from multiple source IPs (post).
- Same day: Citrix published a notice about a "newly observed issue" with SAML authentication and said it was separate from the earlier flaws, per BleepingComputer.
- 3 October: Citrix published bulletin CTX697174.
- 4 October: the NVD record appeared and CISA added the flaw to KEV.
Is it more than a crash?
Citrix and CISA both describe a denial of service, and we are not claiming code execution. But some evidence points further, and none of it is confirmed:
- Beaumont reported that one patched honeypot was "running a downloaded (malware) binary" (post).
- One admin logged crafted SAML usernames carrying shell commands just before the nsaaad process crashed. The admin stressed that the logs showed attempts and correlated crashes, not confirmed execution (BleepingComputer).
- watchTowr says it reproduced the flaw but has not released details (BleepingComputer).
- There is precedent. CVE-2025-6543 was also labelled a "memory overflow ... Denial of Service" and was later used for remote code execution, as Beaumont noted (post).
Plan around the documented impact, but treat an exposed SAML appliance as possibly compromised, not only as a denial-of-service risk.
What defenders should do
- Check whether you are exposed. Citrix gives two configuration checks. An appliance is in scope if its configuration contains either of these commands:
add authentication samlAction (appliance acts as a SAML SP)
add authentication samlIdPProfile (appliance acts as a SAML IdP)
- Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS and NDcPP build, even if you patched in September.
- Meet the KEV date. Federal agencies must act by 7 October under BOD 26-04. CISA's entry also calls for forensic triage requirements to be followed. (We covered another recent overflow flaw on an edge device in KEV.)
- Review exposed appliances as possibly compromised. Treat any SAML-enabled gateway that faced the internet at least since 1 October as a candidate for a compromise check, especially if it was also exposed to the September zero-days.
- Know the signs while you schedule the upgrade. Citrix provides Global Deny Lists that block known malicious IP addresses, but still says to install the update. The visible sign is the nsaaad process crashing until the Pitboss supervisor hits its restart limit and reboots the appliance (BleepingComputer). Beaumont published these
ns.logpatterns to search for:proc nsaaad.*(SIGNALED|EXITED), "maximum number of restarts" and "Pitboss declaring system failure" (post).
Sources
- Citrix security bulletin CTX697174
- Citrix security bulletin CTX697096 (September fixes)
- NVD record for CVE-2026-88779 (API)
- CISA KEV entry
- BleepingComputer coverage (secondary; quotes Citrix's blog post)
- Kevin Beaumont's posts: 2 October honeypot crashes, downloaded binary, CVE-2025-6543 precedent (researcher commentary, not confirmed)