If you run Citrix NetScaler ADC or NetScaler Gateway with SAML authentication, check your build number today. CVE-2026-88779, a memory overflow that can take a SAML-configured appliance offline, is being exploited, and the fix is in builds newer than the ones Citrix shipped for last week’s two zero-days. An appliance upgraded to 14.1-73.37 or 13.1-64.23 on or after September 27 is still inside the affected range.
This article separates what Citrix, CISA and the security researchers have each confirmed, because early reporting mixed denial of service with remote code execution. For the two earlier flaws, see our patch-and-hunt guide for CVE-2026-88771 and CVE-2026-88772.
What is confirmed
NetScaler, acting as its own CVE Numbering Authority (the organization authorized to assign and describe CVE IDs for its products), published the record for CVE-2026-88779 on October 4, 2026 at 02:35 UTC. The record’s public date is 02:19 UTC on October 4, which is the evening of October 3 in US time zones. Sources that say Citrix published its bulletin, CTX697174, on “October 3” and the CVE record’s “October 4” describe the same event in different time zones.
| CVE-2026-88779 | |
|---|---|
| Product | NetScaler ADC and NetScaler Gateway (on-premises) |
| Weakness | Memory buffer bounds error (CWE-119, as classified by CISA), reported as a memory overflow leading to denial of service |
| CVSS 4.0 base score | 8.7 (High); attack over the network, low complexity, no privileges, no user interaction; impact on availability only |
| Affected builds | ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, before 13.1-37.282. Gateway: before 14.1-73.41 and before 13.1-64.28 |
| Fixed in | 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 (FIPS and NDcPP ADC builds) |
| Configuration condition | Appliance configured as a SAML service provider or SAML identity provider, per watchTowr and The Hacker News |
| CISA KEV added | October 4, 2026; due date October 7, 2026 |
CVSS (Common Vulnerability Scoring System) is the standard 0 to 10 severity scale; this score uses version 4.0. KEV is CISA’s Known Exploited Vulnerabilities catalog.
Why last week’s patch level is not enough
The earlier bulletin, CTX697096 of September 27, 2026, fixed CVE-2026-88771 through CVE-2026-88778 in builds 14.1-73.37 and 13.1-64.23 (and 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP ADC). The new record uses “before” ranges that start higher:
| Branch | Fixes the September 27 bulletin (CVE-2026-88771 to -88778) | Fixes CVE-2026-88779 (October 3-4 bulletin) |
|---|---|---|
| 14.1 | 14.1-73.37 | 14.1-73.41 |
| 13.1 | 13.1-64.23 | 13.1-64.28 |
| 14.1 FIPS | 14.1-73.37 FIPS | 14.1-73.41 FIPS |
| 13.1 FIPS and NDcPP (ADC only) | 13.1-37.279 | 13.1-37.282 |
An appliance on 14.1-73.37, for example, is earlier than 14.1-73.41, so the record lists it as affected. SecurityWeek reported that appliances already patched for the earlier flaws were hit; that matches the version arithmetic. The practical consequence is that “we patched the NetScaler last week” is no longer a complete answer, and the target build is the newer one.
Two limits apply. The Gateway records list only the 14.1 and 13.1 non-FIPS builds, which is why the FIPS builds are shown for ADC only. And we did not test any build; this is the reading of the published ranges.
What attackers can do with it, and what is unconfirmed
The evidence supports one consequence: denial of service. CISA’s catalog entry says the flaw “could allow for a denial of service”. Citrix said, as quoted by The Hacker News, that it observed targeted attacks on unmitigated deployments that can lead to denial of service, and that it had not identified an impact on the integrity of customer data. Help Net Security also quotes Citrix as saying that if the condition is triggered repeatedly, the service may remain unavailable.
Several details in early coverage deserve caution:
- Remote code execution. Help Net Security says attackers reportedly attempt to download and install web shells. SOC Prime, citing SecurityWeek, describes authentication requests containing shell commands in username fields and a researcher’s report of a malware binary downloaded on one honeypot. These are described as attempts. None of the sources we read shows code execution through CVE-2026-88779 itself. SecurityWeek reported that watchTowr concluded the flaw is a denial-of-service issue that can only crash systems. The earlier flaws, CVE-2026-88771 and CVE-2026-88772, are the ones for which web shell deployment has been documented, and some of that traffic may be aimed at them.
- Why attackers would crash appliances. watchTowr suspects, according to SecurityWeek, that crashing appliances may be intended to speed up exploitation of CVE-2026-88771. That is a researcher’s hypothesis, not a confirmed attacker goal.
- A reboot after a set number of crashes. One summary we read claims the appliance reboots after a particular number of crashes. We could not confirm that in Citrix’s or watchTowr’s own text, so we are not repeating the number.
- Which flaw caused a given crash. Administrators told reporters that patched appliances were rebooting and that interim workarounds sometimes failed to stop the crashes, per SecurityWeek. Those are reports from the field, not measurements of a specific flaw.
What CISA’s data says
CISA added the flaw to KEV on October 4, 2026 with a due date of October 7, marked forensic triage as required, and listed ransomware campaign use as “Unknown”. The due date comes from Binding Operational Directive 26-04 and applies to US Federal Civilian Executive Branch agencies, not to private organizations; CISA encourages everyone to adopt the same risk-based approach.
CISA’s own enrichment of the CVE record rates exploitation as “active”, the flaw as automatable by an attacker (“yes”), and technical impact as “partial”. The Exploit Prediction Scoring System (EPSS), a model that estimates the chance of exploitation in the next 30 days, gave the flaw 0.00534 (about 0.5%, 43rd percentile) on October 5, 2026. That number is low despite confirmed exploitation. Use it as a reminder that EPSS lags new disclosures, not as a reason to wait.
What to do, in order
This sequence is our recommendation, built on the vendor and researcher guidance cited above.
1. Establish whether SAML is configured
watchTowr says the condition is a SAML service provider or identity provider setup. WorkOS suggests searching the configuration file for the two relevant commands; the search itself changes nothing:
grep -E "add authentication saml(Action|IdPProfile)" /nsconfig/ns.conf
Run it from the appliance shell and read the result against the Citrix bulletin. A match means the appliance meets the described condition. No match is encouraging but the safe default is still to move to the fixed build, since every build you would choose in the next maintenance window should be at or above the newer ones.
2. Upgrade to the new fixed build
Target 14.1-73.41 or later, or 13.1-64.28 or later (or the FIPS and NDcPP builds in the table above). Confirm exact build strings on Citrix’s download page before upgrading FIPS or NDcPP appliances, because our earlier article noted inconsistent formatting of the 13.1 FIPS string in CVE records. Versions 12.1 and 13.0 are end-of-life, and we found no statement on whether they are affected; plan the migration rather than assuming they are not.
3. Apply interim mitigation if you cannot upgrade today
watchTowr and Help Net Security both point to Citrix’s Global Deny List signatures, delivered through NetScaler Console, as the interim step; WorkOS also mentions responder policies available from Citrix Support. SecurityWeek’s reporting that workarounds sometimes failed to stop the crashes means mitigation buys time and is not a substitute for the fixed build.
4. Look for crashes, then for what came with them
WorkOS lists crashes in /var/log/ns.log or /var/log/messages, repeated daemon restarts, “Pitboss declaring system failure” messages and unexplained reboots since late September as signs to look for. Help Net Security reports that Citrix offers an indicator-of-compromise script run through NetScaler Console. We did not run either.
A denial-of-service flaw should not close the investigation. If an appliance rebooted unexpectedly in the past two weeks, check it for the configuration theft and web shell activity described in our CVE-2026-88771 and CVE-2026-88772 article. Preserve logs first; our piece on logging for incidents explains why off-box copies matter.
5. Decide what an outage costs you
Many organizations authenticate staff to everything through the same NetScaler SAML configuration. A flaw that can crash it is an availability risk to every application behind it. Whether you can reach critical systems when the gateway is down is worth testing, and our vulnerability backlog piece covers how to rank exposed and exploited items ahead of the rest. The general sequence for flaws attacked before a patch plan existed is in our zero-day response guide.
What to take from this
Two security bulletins in under a week for one product means the version you recorded last week is stale. Track the fixed build per advisory, not “patched” as a status, and recheck the product’s bulletin page after any exploited-flaw announcement before closing the ticket.
Sources and verification
Checked on October 6, 2026. We did not test the vulnerability, run any script or access a NetScaler appliance. Citrix’s own bulletin pages (CTX697174 and the Citrix community post) returned an access error from our environment, so Citrix’s statements are quoted through the CVE record, CISA data and the secondary reports named in the table.
| Important claim | Source | Verification |
|---|---|---|
| Record published October 4, 2026 02:35 UTC; affects ADC before 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282, and Gateway before 14.1-73.41 and 13.1-64.28 | CVE record via the CVE Program API | Verified |
| CVSS 4.0 base score 8.7 (High), availability impact only; CWE-119 | Same CVE record | Verified: score assigned by NetScaler; CWE assigned by CISA, not NetScaler |
| CISA KEV added October 4, 2026; due October 7; forensic triage required; ransomware use unknown; description says it could allow denial of service | CISA KEV data, catalog version 2026.10.04; CISA alert | Verified |
| BOD 26-04 applies to US federal civilian agencies; CISA encourages all organizations to adopt the approach | CISA alert above | Verified |
| CISA enrichment: exploitation active, automatable yes, technical impact partial | CVE record, CISA ADP section | Verified |
| September 27 bulletin fixed builds were 14.1-73.37 and 13.1-64.23 | FirewallSync article on CVE-2026-88771 and CVE-2026-88772, from NetScaler’s CVE records | Verified: our earlier reporting |
| Condition: SAML service provider or identity provider | watchTowr, October 5, 2026; The Hacker News | Qualified: not stated in NetScaler’s CVE record |
| Citrix: targeted attacks on unmitigated deployments can lead to denial of service; no impact on customer data integrity identified | The Hacker News; SecurityWeek | Qualified: quoted second-hand; Citrix pages not accessible |
| watchTowr concluded denial of service only; suspects use to speed exploitation of CVE-2026-88771 | SecurityWeek | Qualified: researcher assessment and hypothesis |
| Patched appliances reported rebooting; workarounds sometimes failed | SecurityWeek | Qualified: administrator reports |
| Global Deny List signatures as interim mitigation | watchTowr post; Help Net Security, October 5, 2026 | Qualified: Citrix guidance not directly read |
| Log indicators and configuration search command | WorkOS | Qualified: third-party guidance, not run |
| EPSS 0.00534 (43rd percentile) on October 5, 2026 | FIRST EPSS API | Verified: figure changes daily |
Frequently asked questions
I upgraded to 14.1-73.37 or 13.1-64.23 after the September 27 bulletin. Am I protected against CVE-2026-88779?
No. NetScaler's CVE record lists everything before 14.1-73.41 and before 13.1-64.28 as affected. Builds 14.1-73.37 and 13.1-64.23 are earlier than those, so they are in the affected range if SAML is configured.
Does CVE-2026-88779 allow remote code execution?
No source we read confirms that. CISA's catalog entry describes a flaw that 'could allow for a denial of service', NetScaler's record describes denial of service, and watchTowr's published analysis focuses on denial of service only. SecurityWeek reported that watchTowr concluded the flaw can only be used to crash systems. Some reports describe attempts to download malware against honeypots, which shows attackers were probing, not that code execution through this flaw was achieved.
Do I have to meet the CISA deadline of October 7, 2026?
Only if you are a US Federal Civilian Executive Branch agency. CISA says Binding Operational Directive 26-04 applies to those agencies and encourages all organizations to adopt similar risk-based prioritization.
Is my appliance affected if it does not use SAML?
Per NetScaler's description as relayed by watchTowr and The Hacker News, the issue requires the appliance to be configured as a SAML service provider or SAML identity provider. NetScaler's own CVE record lists affected versions without stating the condition, so confirm in your configuration and use the fixed builds regardless when you next upgrade.
