Citrix has released emergency updates for CVE-2026-88779, a high-severity NetScaler memory-overflow vulnerability that attackers exploited as a zero-day against SAML-enabled deployments.
The flaw can trigger denial-of-service conditions in affected customer-managed NetScaler ADC and NetScaler Gateway appliances. Citrix says repeated exploitation can leave the service unavailable, but its current analysis has not identified an impact on customer data integrity.
The Citrix security bulletin assigns CVE-2026-88779 a CVSS 4.0 score of 8.7. Citrix disclosed the vulnerability Oct. 3 and said it had observed targeted attacks against unmitigated deployments.
CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate it by Oct. 7.
CVE-2026-88779 targets SAML-enabled NetScaler deployments
Exposure depends on the appliance configuration.
Citrix says affected NetScaler ADC or NetScaler Gateway deployments must be configured as either a SAML service provider or SAML identity provider. Administrators can check configurations for these entries:
add authentication samlActionfor a SAML service provider.add authentication samlIdPProfilefor a SAML identity provider.
Citrix's accompanying technical guidance also connects the issue to deployments using SAML authentication with Gateway or authentication, authorization, and auditing functionality.
CVE-2026-88779 is categorized as CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer.
Citrix has confirmed targeted exploitation causing denial-of-service conditions. The company has not confirmed remote code execution or an impact on customer-data integrity.
That distinction is important because CVE-2026-88779 follows a separate set of NetScaler vulnerabilities disclosed earlier this year that carried different exploitation conditions and impacts.
Which NetScaler versions need updates
Citrix lists the following customer-managed versions as affected when the SAML prerequisite is present:
- NetScaler ADC and NetScaler Gateway 14.1: versions before 14.1-73.41.
- NetScaler ADC and NetScaler Gateway 13.1: versions before 13.1-64.28.
- NetScaler ADC 14.1-FIPS: versions before 14.1-73.41 FIPS.
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: versions before 13.1-37.282.
Organizations should upgrade to those listed builds or later supported releases.
Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected and need the relevant NetScaler upgrade.
Citrix-managed cloud services, including Gateway Service and Citrix-managed Adaptive Authentication, are handled separately. Citrix says it applies the necessary updates to those managed services itself.
Last week's NetScaler patches are not enough
Organizations that patched NetScaler appliances following last week's disclosure of CVE-2026-88771 through CVE-2026-88778 may still need to update again.
Those earlier vulnerabilities were fixed beginning with NetScaler 14.1-73.37 and 13.1-64.23. CVE-2026-88779 requires 14.1-73.41 or 13.1-64.28, respectively.
Citrix explicitly warns customers whose deployments meet the new SAML prerequisites to install the newer CVE-2026-88779 releases even if they already applied the previous NetScaler security update.
That makes checking the exact build number as important as confirming whether SAML is configured.
Citrix offers temporary virtual-patching protection
Citrix has also released Global Deny List signatures that can reduce exposure while organizations validate affected systems and prepare upgrades.
The mitigation applies only to specific supported builds:
- NetScaler 14.1 from 14.1-73.37 through versions before 14.1-73.41.
- NetScaler 13.1 from 13.1-64.23 through versions before 13.1-64.28.
Using the signatures requires NetScaler Console on-premises with Cloud Connect or the NetScaler Console service, with Virtual Patching enabled.
Administrators can run show appfw signatures and confirm the Default Signatures encrypted version is at least v24. Citrix also recommends checking Global Deny List counters with stat denylist global AAA_REQUEST to verify that the rules are being evaluated.
Citrix describes the signatures as a mitigation, not a replacement for installing the fixed software.
What defenders should do now
Security teams responsible for NetScaler should prioritize four actions:
- Check SAML configuration: Determine whether appliances contain
samlActionorsamlIdPProfileentries and therefore meet the CVE prerequisites. - Verify exact build numbers: Systems patched for the previous NetScaler zero-days may still be vulnerable to CVE-2026-88779.
- Upgrade to the new fixed releases: Move to 14.1-73.41, 13.1-64.28, or the corresponding FIPS and NDcPP builds as applicable.
- Review suspicious activity: Investigate abnormal service crashes, repeated availability problems, and other signs of exploitation, then follow established incident-response procedures where compromise is suspected.
Organizations temporarily relying on Citrix's Global Deny List should verify that the signatures are installed and active while scheduling the full software upgrade.
CVE-2026-88779 is separate from CVE-2026-88771 and CVE-2026-88772, the two NetScaler RCE zero-days disclosed in late September. Defenders that already responded to that incident should not assume those patches also close this newly disclosed SAML flaw.
Also read: Citrix recently patched two NetScaler RCE zero-days that attackers exploited globally before CVE-2026-88779 was disclosed.





