The short answer
CVE-2026-88779 is an actively exploited memory overflow in Citrix NetScaler ADC and Gateway that only affects appliances doing SAML, either as a Service Provider or as an Identity Provider. Citrix rates it CVSS 8.7 and describes the impact as denial of service. CISA listed it as known exploited on October 4, 2026 and set an October 7 deadline for federal agencies.
The awkward part is timing. The builds that fixed the NetScaler remote code execution zero-days a week ago do not fix this one, so SAML-enabled appliances need a second emergency upgrade. If the gateway in front of your apps handles single sign-on, treat this as a production change for this week and run it through the same cloud and DevOps release process you use for the services behind it.
What did Citrix disclose?
Citrix published security bulletin CTX697174 for CVE-2026-88779, a memory overflow in the SAML authentication path of NetScaler ADC and NetScaler Gateway. In its own words, Citrix “has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.” A crafted request crashes the appliance, and an attacker who repeats it can keep the gateway, and every login that depends on it, unavailable.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 4, 2026 and gave US federal civilian agencies until October 7 to fix it, a three-day window that signals how seriously it rates the activity. The Hacker News credits Bishop Fox and watchTowr with the report.
There is one open question. Citrix classifies the bug as denial of service only, but BleepingComputer reported that some administrators saw login attempts where the username field carried shell commands to download a payload. That points to attackers at least trying to turn the overflow into code execution. It is not confirmed, and the conservative reading is: plan for denial of service, investigate as if code execution were possible.
Which NetScaler deployments are exposed?
Unlike last week’s CVE-2026-88771, which hit default configurations, this flaw needs SAML. An appliance is in scope if it acts as a SAML Service Provider, for example when NetScaler Gateway hands VPN or Citrix Workspace logins to Microsoft Entra ID or Okta, or as a SAML Identity Provider issuing assertions to other apps. In practice that covers many enterprise remote-access setups, because SAML single sign-on is the standard way to put MFA in front of a NetScaler.
The fixed builds are 14.1-73.41 and 13.1-64.28. The late-September builds 14.1-73.37 and 13.1-64.23, which closed CVE-2026-88771 through CVE-2026-88778, are still vulnerable. Versions 12.1 and 13.0 are end of life and receive no fixes. For teams that just finished one emergency change on these appliances, this is the second in about a week.
What it means for US & EU software teams
First, your identity layer now has a single point of failure you may not have mapped. When the gateway that performs SAML goes down, every app behind it loses sign-in, even if the apps themselves are healthy. Engineering teams should know which customer-facing and internal services depend on that path, what the break-glass login is, and how long the business can run without it.
Second, “patched last week” is not a status. NetScaler has needed three separate emergency builds in under two months. Edge appliances need the same version tracking as container images and dependencies, with alerts tied to the newest advisory rather than to a closed ticket.
Third, an outage on the authentication path is still a reportable security event. For EU organizations under NIS2, and financial entities under DORA, a deliberate attack that takes down access to essential services can trigger incident classification and reporting duties even without data theft. If the reported code-execution attempts turn out to be real, GDPR breach assessment comes into play as well. Keep the evidence that shows which of the two happened.
What should you do now?
- Find the SAML appliances. Search every NetScaler configuration, including DR and lab units, for
add authentication samlActionandadd authentication samlIdPProfile, and record the exact build of each match. - Preserve evidence, then upgrade. Save logs, crash dumps and configuration, then move SAML-enabled appliances to 14.1-73.41, 13.1-64.28 or the matching FIPS build. Appliances on 12.1 or 13.0 must move to a supported branch.
- Plan the sign-in outage. Upgrading the box that performs SAML interrupts logins. Schedule it, warn users and keep a tested non-SAML admin path in case the upgrade fails.
- Hunt for attempts. Review authentication logs and crash records since late September for malformed SAML requests, unexpected restarts and usernames containing commands or URLs. Check the identity provider for unusual assertion activity.
- Close the loop. Add NetScaler builds to automated version monitoring and include the SSO path in your next security test.
Frequently asked questions
What is CVE-2026-88779?
It is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway, rated CVSS 8.7, published in Citrix bulletin CTX697174. Citrix describes the impact as denial of service: crafted SAML traffic can crash the appliance, and repeated attacks can keep authentication services offline. Bishop Fox and watchTowr are credited with reporting it.
Is my NetScaler affected by CVE-2026-88779?
Only if it is configured as a SAML Service Provider (an 'add authentication samlAction' entry in ns.conf) or as a SAML Identity Provider (an 'add authentication samlIdPProfile' entry) and runs a build older than 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP. Appliances that use SAML for single sign-on to Microsoft Entra ID, Okta or another identity provider usually meet the condition.
Is CVE-2026-88779 being exploited?
Yes. Citrix says it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. CISA added the CVE to its Known Exploited Vulnerabilities catalog on October 4, 2026 and gave US federal civilian agencies until October 7 to fix it. BleepingComputer reported that some administrators saw crafted login usernames containing shell commands, which suggests attackers may be trying to reach code execution; Citrix has not confirmed that.
We patched NetScaler last week for CVE-2026-88771 and 88772. Are we covered?
No. The late-September builds 14.1-73.37 and 13.1-64.23 fixed CVE-2026-88771 to CVE-2026-88778 but not CVE-2026-88779. SAML-enabled appliances need 14.1-73.41, 13.1-64.28 or the matching FIPS build, which means a second emergency upgrade within about a week.
What should we do besides installing the patch?
Confirm which appliances have SAML configured, preserve logs before upgrading, and review authentication logs and crash records since late September for malformed SAML requests, unexpected restarts or odd usernames. Plan for a short sign-in outage during the upgrade, keep a non-SAML break-glass admin path, and check that the identity provider side has not logged unusual assertions.
Sources
Citrix — NetScaler ADC and NetScaler Gateway Security Bulletin CTX697174 (CVE-2026-88779)
CISA — CISA Adds One Known Exploited Vulnerability to Catalog (Oct 4, 2026)
BleepingComputer — Citrix patches NetScaler SAML zero-day exploited in attacks
The Hacker News — New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline