What is Citrix NetScaler?
NetScaler ADC is Citrix's application delivery controller: a network appliance that terminates TLS, load balances traffic, and applies web application firewall policy at the edge of an enterprise network. NetScaler Gateway is the same platform configured for remote access, providing VPN and single sign-on into internal applications. Many deployments also act as a SAML Service Provider or SAML Identity Provider, brokering authentication between users and an identity provider such as Entra ID or Okta. That places the appliance on the public internet, in front of every remote worker, and on the critical path for logins. If it stops answering, remote access for the whole organization stops with it.
Overview
CVE-2026-88779 is a memory overflow in the SAML authentication handling of NetScaler ADC and NetScaler Gateway. An unauthenticated attacker who can reach the SAML endpoint can corrupt memory in the authentication daemon and take the appliance into a denial of service. Citrix scores it 8.7 High under CVSS 4.0 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H), availability impact only. NVD had not published its own score when this page was written, so the site severity remains unset.
The vulnerability is configuration dependent. Only appliances with SAML configured are affected, meaning the running config contains add authentication samlAction (Service Provider role) or add authentication samlIdPProfile (Identity Provider role), bound to a Gateway or AAA virtual server. Appliances doing plain load balancing, or gateways using LDAP or RADIUS authentication without SAML, do not meet the precondition.
It surfaced as a side effect of the previous NetScaler emergency. After the 2026-09-27 bulletin CTX697096 fixed eight vulnerabilities including the actively exploited CVE-2026-88771 and CVE-2026-88772, administrators who had patched to 14.1-73.37 reported that their appliances kept rebooting anyway. Citrix confirmed on 2026-10-02 that it was tracking a separate SAML-related issue independent of CTX697096, published CTX697174 on 2026-10-03, and the CVE was assigned and added to KEV on 2026-10-04. Citrix states it has observed targeted attacks on unmitigated deployments and that the issue affects availability, with no identified impact on the integrity of customer data.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | before 14.1-73.41 | 14.1-73.41 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | before 13.1-64.28 | 13.1-64.28 and later |
| NetScaler ADC 14.1 FIPS | before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later |
| NetScaler ADC 13.1 FIPS / NDcPP | before 13.1-37.282 | 13.1-37.282 and later |
The 14.1-73.37 and 13.1-64.23 builds released for CTX697096 are vulnerable. Patching for the September zero-days is not sufficient. Citrix-managed cloud instances were patched by Citrix; only customer-managed appliances need action. Secure Private Access Hybrid deployments backed by an affected NetScaler must also be upgraded. End-of-life branches receive no fix.
Technical Details
The CWE assignment is CWE-119, improper restriction of operations within the bounds of a memory buffer: code reads or writes outside the memory region it was allocated, typically because a length taken from attacker-controlled input is used without checking it against the buffer size. Here the input is a SAML message, so the attacker controls a verbose, structured XML blob that the appliance must parse before it can authenticate anyone, which is why no credentials are needed.
Community reports during the pre-advisory period point at nsaaad, the NetScaler AAA authentication daemon, crashing on malformed SAML requests and taking the appliance into a failover or a full reboot. Citrix notes that if the condition is triggered repeatedly the service can remain unavailable, so a single attacker can hold a gateway down with a loop rather than a one-shot crash. Citrix has not published the parsing routine, the SAML element involved, or whether the overflow is a read or a write, and no public proof-of-concept or patch-diff analysis existed at the time of writing. Treat the specific memory primitive as unknown.
Discovery
No external security researcher is credited. The issue became visible through NetScaler administrators on Reddit and community forums reporting unexplained reboots on freshly patched appliances in the days after 2026-09-27, with some describing payload-bearing requests and attempted script downloads alongside the crashes. Citrix engineering and support correlated those reports, confirmed a configuration-dependent SAML defect distinct from CTX697096, and issued CTX697174 on 2026-10-03.
Exploitation Context
Citrix states it has observed targeted attacks against unmitigated deployments, and CISA added the CVE to the KEV catalog on 2026-10-04 with a three-day remediation deadline. The confirmed effect is denial of service: repeated crashes of the authentication service, failovers between high availability nodes, and appliance reboots that cut remote access.
Exposure numbers published during this campaign count NetScaler appliances reachable from the internet, not appliances meeting this CVE's SAML precondition. Shadowserver reported more than 20,000 exposed instances in late September 2026, and other counts ran higher. The vulnerable subset is smaller but unknown, since SAML configuration is not externally enumerable with confidence.
No threat actor has been attributed to this CVE specifically. It lands in the middle of an ongoing campaign against NetScaler in which Google Threat Intelligence Group and Mandiant assessed the CVE-2026-88771 and CVE-2026-88772 operators as sophisticated and state-nexus aligned, deploying the Whipshot webshell and the Slapshot Python tunneler, with Arctic Wolf counting at least 78 affected organizations across North America and Europe. There is no public evidence that CVE-2026-88779 is chained with those flaws; it yields availability loss only, and the preconditions differ.
Remediation
- Upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 as applicable. Citrix has published no official workaround, and these builds supersede the CTX697096 fixes.
- Determine whether you meet the precondition before deprioritizing. Check the running config for
add authentication samlActionandadd authentication samlIdPProfileand confirm whether those policies are bound to an internet-facing Gateway or AAA virtual server. The community read-only checker for CTX697096 and CTX697174 covers this test. - If you cannot patch immediately, restrict who can reach the SAML endpoint. Source IP restrictions on the virtual server, upstream firewall rules, or Global Deny List signatures applied through NetScaler Console narrow the attack surface. Removing SAML authentication from an internet-facing virtual server removes the precondition, at the cost of breaking single sign-on.
- Verify every node. In a high availability pair or cluster, confirm the build on each member; mixed builds have produced confusing reboot behaviour during this incident.
- Review logs for repeated
nsaaadcrashes, unexplained failovers, reboot loops, and bursts of malformed SAML POSTs to the Gateway or AAA virtual server. Preserve crash artifacts and core dumps before restarting, since a reboot discards them. - Treat crashes on an appliance that was unpatched for CTX697096 as a possible symptom of more than denial of service. Follow Citrix CTX694799 if compromise is plausible: rotate credentials the appliance held, replace TLS keys and certificates, terminate active sessions, and run the IOC scan available in NetScaler Console.
- Federal civilian agencies were required to remediate by 2026-10-07 under BOD 26-04 and to perform the forensic triage the directive specifies.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2026-88779 |
| Vendor / Product | Citrix — NetScaler |
| CVSS 3.1 Score | Pending |
| Severity | UNKNOWN |
| CWE | CWE-119 find similar ↗ |
| CISA KEV Added | 2026-10-04 |
| CISA KEV Deadline | 2026-10-07 |
| Known Ransomware Use | No |
Required Action
Timeline
| Date | Event |
|---|---|
| 2026-09-27 | Citrix publishes CTX697096 for CVE-2026-88771 through CVE-2026-88778; CISA adds the two exploited zero-days to the KEV catalog |
| 2026-10-02 | Administrators report that appliances patched for CTX697096 keep rebooting; Citrix confirms a separate, configuration-dependent SAML issue |
| 2026-10-03 | Citrix publishes security bulletin CTX697174 with fixed builds |
| 2026-10-04 | CVE-2026-88779 record published; CISA adds it to the Known Exploited Vulnerabilities catalog |
| 2026-10-07 | CISA BOD 26-04 remediation deadline |