TL;DR
Citrix has assigned Citrix NetScaler CVE-2026-88779 to the SAML issue behind recent appliance reboots. The company confirms attackers are exploiting the memory overflow flaw in the wild. Fixed builds 14.1-73.41 and 13.1-64.28 are now available.
- CVE: CVE-2026-88779
- CVSS: 8.7 (High · CVSSv4)
- Product: NetScaler ADC
- Affected: < 14.1-73.41, < 13.1-64.28, < 14.1-73.41 FIPS, < 13.1-37.282
- Impact: Memory overflow vulnerability leading to Denial of Service
- Status: Exploited in the wild
- Patched in: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282
- Action: Update to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 now
Running Infra, AppSec, and SOC teams? Tag Citrix alerts by team automatically.
Try Team free for 14 daysWhy It Matters
This week, admins in a Reddit thread on NetScaler attacks after patching described internet-facing appliances rebooting over and over. Many of those devices already ran 14.1-73.37, the build that fixed September’s NetScaler zero-days. Citrix then warned of a separate SAML authentication issue but gave no CVE or fix.
Now Citrix has filled that gap. It says it “has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.”
How the Attack Works
CVE-2026-88779 is a memory buffer flaw (CWE-119) with a CVSS 4.0 score of 8.7. It affects appliances that use NetScaler SAML authentication with a Gateway or AAA virtual server. According to Citrix, “If the condition is triggered repeatedly, the service may remain unavailable.” However, Citrix has found no impact on the integrity of customer data.
Exposure depends on configuration. Affected units contain “add authentication samlAction” or “add authentication samlIdPProfile.”
Affected Versions
- NetScaler ADC and Gateway 14.1 before 14.1-73.41
- NetScaler ADC and Gateway 13.1 before 13.1-64.28
- NetScaler ADC FIPS before 14.1-73.41 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.282
Only customer-managed appliances need action. Citrix already updated its managed cloud services.
Patch and Mitigation Steps
First, check your configuration for the two SAML commands. Next, upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS and NDcPP build. Admins who patched for the September bulletins must upgrade again if they use SAML. Until then, Citrix offers Global Deny List signatures through NetScaler Console as a stopgap. Firewall blocks on attacking IP addresses add another layer.
Full steps appear in Citrix’s guide to understanding and addressing CVE-2026-88779. Given the confirmed attacks, Citrix NetScaler CVE-2026-88779 should top every patch queue.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!