Citrix published CTX697174 for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway. CISA added it to the Known Exploited Vulnerabilities catalog on 4 October 2026, with a federal due date of 7 October.
Citrix rates it 8.7 and describes denial of service when the appliance is a SAML service provider or SAML identity provider. No login is required to crash the SAML handler. This is a separate issue from the September RCE pair, CVE-2026-88771 and CVE-2026-88772. Appliances patched for those still need this build if they use SAML.
What happened
The overflow sits in SAML request handling. A crafted request can take the authentication service down and cut VPN or SSO that depends on it. Citrix and CISA both treat exploitation as confirmed. Citrix has not confirmed remote code execution for this CVE. Some researchers have raised that possibility. Treat it as unconfirmed.
Who is affected
NetScaler ADC and Gateway 14.1 before 14.1-73.41, and 13.1 before 13.1-64.28, when configured as a SAML SP or SAML IdP. Matching FIPS and NDcPP builds before 14.1-73.41 FIPS and 13.1-37.282 are also listed.
What to do now
- Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS build, then run forensic triage on internet-facing appliances.
- Confirm whether each virtual server uses SAML. That is the precondition Citrix names.
- Do not stop at the late-September RCE patches. This bulletin is a second upgrade.
- Watch for SAML authentication failures followed by a service crash.
Source: Citrix security bulletin CTX697174 and the CISA KEV entry. Read the advisory.
Also on the blog
- Atlassian CVE-2026-21589: unauthenticated file read on 8 products
- CVE-2026-104286: FortiMail unauthenticated file write, CVSS 9.8
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- ClickFix cache smuggling bypasses the Windows Run character limit
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.