CVE-2026-88779: NetScaler SAML crash, KEV due 7 October
Memory overflow in NetScaler ADC and Gateway SAML, actively exploited

CVE-2026-88779: NetScaler SAML crash, KEV due 7 October

Citrix published CTX697174 for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway. CISA added it to the Known Exploited Vulnerabilities catalog on 4 October 2026, with a federal due date of 7 October.

Citrix rates it 8.7 and describes denial of service when the appliance is a SAML service provider or SAML identity provider. No login is required to crash the SAML handler. This is a separate issue from the September RCE pair, CVE-2026-88771 and CVE-2026-88772. Appliances patched for those still need this build if they use SAML.

What happened

The overflow sits in SAML request handling. A crafted request can take the authentication service down and cut VPN or SSO that depends on it. Citrix and CISA both treat exploitation as confirmed. Citrix has not confirmed remote code execution for this CVE. Some researchers have raised that possibility. Treat it as unconfirmed.

Who is affected

NetScaler ADC and Gateway 14.1 before 14.1-73.41, and 13.1 before 13.1-64.28, when configured as a SAML SP or SAML IdP. Matching FIPS and NDcPP builds before 14.1-73.41 FIPS and 13.1-37.282 are also listed.

What to do now

  • Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS build, then run forensic triage on internet-facing appliances.
  • Confirm whether each virtual server uses SAML. That is the precondition Citrix names.
  • Do not stop at the late-September RCE patches. This bulletin is a second upgrade.
  • Watch for SAML authentication failures followed by a service crash.

Source: Citrix security bulletin CTX697174 and the CISA KEV entry. Read the advisory.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-104286: FortiMail unauthenticated file write, CVSS 9.8
Path traversal on FortiMail, exploited, KEV due date already passed