Citrix has patched a memory overflow in NetScaler ADC and NetScaler Gateway that attackers are already using to knock SAML deployments offline. The bug, CVE-2026-88779, scores 8.7. CISA added it to the Known Exploited Vulnerabilities catalog and set a federal deadline of 7 October 2026.
What happened
Citrix says it has seen targeted attacks on unpatched customer-managed appliances. Repeated triggers can keep the service down. The vendor says its analysis points to availability impact, not to a confirmed hit on customer data integrity.
The flaw only bites when the appliance is a SAML service provider or SAML identity provider, used with Gateway or AAA. Look for add authentication samlAction or add authentication samlIdPProfile in the config.
This landed days after two earlier NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were already being used to plant web shells. Admins who patched those builds over the weekend still need this newer fix. Researchers have reported crash loops, and it is not yet clear whether this overflow can also be turned into remote code execution.
Who is affected
Customer-managed NetScaler ADC and Gateway on supported branches below the fixed builds, if SAML is configured. Cloud-managed services are outside this bulletin.
- 14.1 before 14.1-73.41, including 14.1-FIPS
- 13.1 before 13.1-64.28
- 13.1-FIPS and 13.1-NDcPP before 13.1-37.282
What to do now
Upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS build, then run the Citrix indicator-of-compromise script and keep the output before you reboot. Citrix has also pushed Global Deny List signatures for known malicious addresses while you schedule the change. Treat a reboot loop on a freshly patched SAML appliance as an incident, not a bad upgrade.
Source: The Hacker News, 5 October 2026. CISA catalog note: CISA, 4 October 2026.
Also on the blog
- FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- Atlassian CVE-2026-21589 (CVSS 9.3) file read on 8 products
- Dell DSU CVE-2026-86360 (CVSS 9.6) root on PowerEdge updates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.