CVE-2026-88779 — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

CVE-2026-88779

Citrix NetScaler ADC and Gateway - Pre-Auth SAML Memory Overflow Denial of Service

What is Citrix NetScaler?

NetScaler ADC is Citrix's application delivery controller: a network appliance that terminates TLS, load balances traffic, and applies web application firewall policy at the edge of an enterprise network. NetScaler Gateway is the same platform configured for remote access, providing VPN and single sign-on into internal applications. Many deployments also act as a SAML Service Provider or SAML Identity Provider, brokering authentication between users and an identity provider such as Entra ID or Okta. That places the appliance on the public internet, in front of every remote worker, and on the critical path for logins. If it stops answering, remote access for the whole organization stops with it.

Overview

CVE-2026-88779 is a memory overflow in the SAML authentication handling of NetScaler ADC and NetScaler Gateway. An unauthenticated attacker who can reach the SAML endpoint can corrupt memory in the authentication daemon and take the appliance into a denial of service. Citrix scores it 8.7 High under CVSS 4.0 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H), availability impact only. NVD had not published its own score when this page was written, so the site severity remains unset.

The vulnerability is configuration dependent. Only appliances with SAML configured are affected, meaning the running config contains add authentication samlAction (Service Provider role) or add authentication samlIdPProfile (Identity Provider role), bound to a Gateway or AAA virtual server. Appliances doing plain load balancing, or gateways using LDAP or RADIUS authentication without SAML, do not meet the precondition.

It surfaced as a side effect of the previous NetScaler emergency. After the 2026-09-27 bulletin CTX697096 fixed eight vulnerabilities including the actively exploited CVE-2026-88771 and CVE-2026-88772, administrators who had patched to 14.1-73.37 reported that their appliances kept rebooting anyway. Citrix confirmed on 2026-10-02 that it was tracking a separate SAML-related issue independent of CTX697096, published CTX697174 on 2026-10-03, and the CVE was assigned and added to KEV on 2026-10-04. Citrix states it has observed targeted attacks on unmitigated deployments and that the issue affects availability, with no identified impact on the integrity of customer data.

Affected Versions

Product Vulnerable Fixed
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 14.1-73.41 and later
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 13.1-64.28 and later
NetScaler ADC 14.1 FIPS before 14.1-73.41 FIPS 14.1-73.41 FIPS and later
NetScaler ADC 13.1 FIPS / NDcPP before 13.1-37.282 13.1-37.282 and later

The 14.1-73.37 and 13.1-64.23 builds released for CTX697096 are vulnerable. Patching for the September zero-days is not sufficient. Citrix-managed cloud instances were patched by Citrix; only customer-managed appliances need action. Secure Private Access Hybrid deployments backed by an affected NetScaler must also be upgraded. End-of-life branches receive no fix.

Technical Details

The CWE assignment is CWE-119, improper restriction of operations within the bounds of a memory buffer: code reads or writes outside the memory region it was allocated, typically because a length taken from attacker-controlled input is used without checking it against the buffer size. Here the input is a SAML message, so the attacker controls a verbose, structured XML blob that the appliance must parse before it can authenticate anyone, which is why no credentials are needed.

Community reports during the pre-advisory period point at nsaaad, the NetScaler AAA authentication daemon, crashing on malformed SAML requests and taking the appliance into a failover or a full reboot. Citrix notes that if the condition is triggered repeatedly the service can remain unavailable, so a single attacker can hold a gateway down with a loop rather than a one-shot crash. Citrix has not published the parsing routine, the SAML element involved, or whether the overflow is a read or a write, and no public proof-of-concept or patch-diff analysis existed at the time of writing. Treat the specific memory primitive as unknown.

Discovery

No external security researcher is credited. The issue became visible through NetScaler administrators on Reddit and community forums reporting unexplained reboots on freshly patched appliances in the days after 2026-09-27, with some describing payload-bearing requests and attempted script downloads alongside the crashes. Citrix engineering and support correlated those reports, confirmed a configuration-dependent SAML defect distinct from CTX697096, and issued CTX697174 on 2026-10-03.

Exploitation Context

Citrix states it has observed targeted attacks against unmitigated deployments, and CISA added the CVE to the KEV catalog on 2026-10-04 with a three-day remediation deadline. The confirmed effect is denial of service: repeated crashes of the authentication service, failovers between high availability nodes, and appliance reboots that cut remote access.

Exposure numbers published during this campaign count NetScaler appliances reachable from the internet, not appliances meeting this CVE's SAML precondition. Shadowserver reported more than 20,000 exposed instances in late September 2026, and other counts ran higher. The vulnerable subset is smaller but unknown, since SAML configuration is not externally enumerable with confidence.

No threat actor has been attributed to this CVE specifically. It lands in the middle of an ongoing campaign against NetScaler in which Google Threat Intelligence Group and Mandiant assessed the CVE-2026-88771 and CVE-2026-88772 operators as sophisticated and state-nexus aligned, deploying the Whipshot webshell and the Slapshot Python tunneler, with Arctic Wolf counting at least 78 affected organizations across North America and Europe. There is no public evidence that CVE-2026-88779 is chained with those flaws; it yields availability loss only, and the preconditions differ.

Remediation

  1. Upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 as applicable. Citrix has published no official workaround, and these builds supersede the CTX697096 fixes.
  2. Determine whether you meet the precondition before deprioritizing. Check the running config for add authentication samlAction and add authentication samlIdPProfile and confirm whether those policies are bound to an internet-facing Gateway or AAA virtual server. The community read-only checker for CTX697096 and CTX697174 covers this test.
  3. If you cannot patch immediately, restrict who can reach the SAML endpoint. Source IP restrictions on the virtual server, upstream firewall rules, or Global Deny List signatures applied through NetScaler Console narrow the attack surface. Removing SAML authentication from an internet-facing virtual server removes the precondition, at the cost of breaking single sign-on.
  4. Verify every node. In a high availability pair or cluster, confirm the build on each member; mixed builds have produced confusing reboot behaviour during this incident.
  5. Review logs for repeated nsaaad crashes, unexplained failovers, reboot loops, and bursts of malformed SAML POSTs to the Gateway or AAA virtual server. Preserve crash artifacts and core dumps before restarting, since a reboot discards them.
  6. Treat crashes on an appliance that was unpatched for CTX697096 as a possible symptom of more than denial of service. Follow Citrix CTX694799 if compromise is plausible: rotate credentials the appliance held, replace TLS keys and certificates, terminate active sessions, and run the IOC scan available in NetScaler Console.
  7. Federal civilian agencies were required to remediate by 2026-10-07 under BOD 26-04 and to perform the forensic triage the directive specifies.

Key Details

PropertyValue
CVE ID CVE-2026-88779
Vendor / Product Citrix — NetScaler
CVSS 3.1 ScorePending
SeverityUNKNOWN
CWE CWE-119 find similar ↗
CISA KEV Added2026-10-04
CISA KEV Deadline2026-10-07
Known Ransomware Use No

Required Action

CISA BOD 22-01 Deadline: 2026-10-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2026-09-27Citrix publishes CTX697096 for CVE-2026-88771 through CVE-2026-88778; CISA adds the two exploited zero-days to the KEV catalog
2026-10-02Administrators report that appliances patched for CTX697096 keep rebooting; Citrix confirms a separate, configuration-dependent SAML issue
2026-10-03Citrix publishes security bulletin CTX697174 with fixed builds
2026-10-04CVE-2026-88779 record published; CISA adds it to the Known Exploited Vulnerabilities catalog
2026-10-07CISA BOD 26-04 remediation deadline