Citrix has rushed out emergency patches for a new actively exploited zero-day in NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the flaw is a memory overflow that attackers can trigger remotely to knock SAML authentication infrastructure offline, and the US Cybersecurity and Infrastructure Security Agency (CISA) has already added it to its Known Exploited Vulnerabilities catalog with a patch deadline of October 7, 2026.
The short version: if your NetScaler is configured as a SAML service provider or identity provider, and it is running an affected build, assume it can be crashed by an unauthenticated attacker right now. Patching cannot wait.
What Is CVE-2026-88779?
CVE-2026-88779 is a memory overflow vulnerability (CWE-119) in customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances. It carries a CVSS v4 score of 8.7, and exploitation requires no authentication and no interaction from a victim.
The critical detail is the precondition: the flaw only triggers when a NetScaler deployment is configured to operate as either a SAML Service Provider (SP) or a SAML Identity Provider (IdP). That narrows the attack surface, but for organizations that run single sign-on, federated identity, or AAA authentication through NetScaler, the impact is direct: Citrix says a successful attack leads to denial of service, and if the condition is triggered repeatedly, the service may stay unavailable.
Citrix has confirmed it has observed targeted attacks against unpatched deployments. The vulnerability was reported by Bishop Fox and watchTowr, the latter noting it could reproduce the flaw within hours of spotting suspicious NetScaler honeypot activity.
Which NetScaler Versions Are Affected?
Citrix has published fixed builds for every affected branch. You are vulnerable if you run anything earlier than the versions below:
Patched versions (upgrade to at least these)
- NetScaler ADC and NetScaler Gateway 14.1: upgrade to 14.1-73.41 or later
- NetScaler ADC and NetScaler Gateway 13.1: upgrade to 13.1-64.28 or later
- NetScaler ADC 14.1-FIPS: upgrade to 14.1-73.41 FIPS or later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: upgrade to 13.1-37.282 or later
Secure Private Access hybrid deployments running affected NetScaler instances also need to be upgraded.
How to Check If You Are Exposed
Before scheduling the patch, confirm whether the precondition applies to your environment. Review your NetScaler configuration for SAML entries matching either of these patterns:
- SAML Service Provider: add authentication samlAction
- SAML Identity Provider: add authentication samlIdPProfile
If neither appears, your deployment is not exposed to this specific flaw, though you should still treat NetScaler as a high-priority patch target. NetScaler appliances are a favorite target of attackers: just last week, researchers reported active exploitation of two earlier NetScaler flaws (CVE-2026-88771 and CVE-2026-88772) to plant web shells and tunneling tools on compromised systems. If you run NetScaler in any internet-facing role, assume it is on somebody’s target list. Our earlier breakdown of the Citrix NetScaler zero-day wave explains how quickly these flaws move from disclosure to weaponization.
What to Do Right Now
1. Patch immediately
Upgrade affected NetScaler ADC and Gateway appliances to the fixed builds listed above. Federal agencies are required by CISA to remediate by October 7, 2026, and everyone else should treat that date as their own deadline at the latest.
2. Restrict access where possible
Limit management and SAML endpoint exposure to trusted networks while patches roll out. Any internet-facing authentication infrastructure should have monitoring in place for repeated availability drops, since sustained exploitation keeps the service offline.
3. Watch for escalation
Right now Citrix says the impact is limited to availability: it has not identified an impact on the integrity of customer data. But researchers are still investigating whether the flaw can be pushed beyond denial of service toward remote code execution. Until that question is settled, treat repeated DoS events as a possible precursor and investigate them with the same seriousness you would give a compromise attempt. The recent Warlock ransomware attacks via an unpatched SharePoint server are a reminder of how one unpatched edge appliance can turn into a full network takeover.
4. Tighten your patching routine
Zero-days in edge appliances are no longer rare events. Our coverage of the recent Apple zero-day CVE-2026-86950 followed the same pattern: disclosure, targeted exploitation, emergency patch. Build a 24-to-48-hour patch SLA for internet-facing infrastructure, and subscribe to Citrix security advisories and the CISA KEV catalog so the next bulletin reaches you before the attackers do.
Frequently Asked Questions
What is CVE-2026-88779?
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway with a CVSS score of 8.7. It can be exploited remotely, without authentication, to cause denial of service on deployments configured as SAML service providers or identity providers. It is being actively exploited in targeted attacks.
Is my NetScaler affected by CVE-2026-88779?
You are affected if your customer-managed NetScaler ADC or NetScaler Gateway runs a supported version earlier than 14.1-73.41 (14.1 branch), 13.1-64.28 (13.1 branch), or the matching FIPS/NDcPP builds, and it is configured as a SAML SP (add authentication samlAction) or SAML IdP (add authentication samlIdPProfile). Check your configuration to confirm.
Can attackers steal data with CVE-2026-88779?
Based on Citrix’s current analysis, the vulnerability affects service availability, not data confidentiality or integrity. However, researchers are still investigating whether it can be escalated to remote code execution, so the assessment could change. Patch now rather than waiting for a revised analysis.
What is the patch deadline for CVE-2026-88779?
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to apply patches by October 7, 2026. Private organizations should aim to patch by the same date at the latest.
How do I fix CVE-2026-88779?
Upgrade to a fixed build: 14.1-73.41 or later, 13.1-64.28 or later, or the corresponding FIPS/NDcPP builds for your branch. Secure Private Access hybrid deployments using affected NetScaler instances must also be upgraded.
