NetScaler CVE-2026-88779 (CVSS 8.7) crashes SAML appliances
Citrix NetScaler SAML memory overflow zero-day

NetScaler CVE-2026-88779 (CVSS 8.7) crashes SAML appliances

Citrix has patched a memory overflow in NetScaler ADC and NetScaler Gateway that attackers are already using to knock SAML deployments offline. The bug, CVE-2026-88779, scores 8.7. CISA added it to the Known Exploited Vulnerabilities catalog and set a federal deadline of 7 October 2026.

What happened

Citrix says it has seen targeted attacks on unpatched customer-managed appliances. Repeated triggers can keep the service down. The vendor says its analysis points to availability impact, not to a confirmed hit on customer data integrity.

The flaw only bites when the appliance is a SAML service provider or SAML identity provider, used with Gateway or AAA. Look for add authentication samlAction or add authentication samlIdPProfile in the config.

This landed days after two earlier NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were already being used to plant web shells. Admins who patched those builds over the weekend still need this newer fix. Researchers have reported crash loops, and it is not yet clear whether this overflow can also be turned into remote code execution.

Who is affected

Customer-managed NetScaler ADC and Gateway on supported branches below the fixed builds, if SAML is configured. Cloud-managed services are outside this bulletin.

  • 14.1 before 14.1-73.41, including 14.1-FIPS
  • 13.1 before 13.1-64.28
  • 13.1-FIPS and 13.1-NDcPP before 13.1-37.282

What to do now

Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS build, then run the Citrix indicator-of-compromise script and keep the output before you reboot. Citrix has also pushed Global Deny List signatures for known malicious addresses while you schedule the change. Treat a reboot loop on a freshly patched SAML appliance as an incident, not a bad upgrade.

Source: The Hacker News, 5 October 2026. CISA catalog note: CISA, 4 October 2026.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

FBI removes Accenture contractor after missed PeopleSoft patch
ShinyHunters theft of FBI employee data tied to a third-party patch failure