A flaw that lets an unauthenticated attacker take down Citrix NetScaler ADC and Gateway has been published.
Citrix (Cloud Software Group) published it as CTX697174, and the CVE record went public on 4 October 2026. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog the same day. The ID is CVE-2026-88779, a memory overflow (CWE-119) leading to denial of service (DoS).
The precondition is that the appliance is configured as a SAML SP or a SAML IdP. Without that, the precondition is not met.
What to do now
- ✓First check whether your NetScaler is a SAML SP or SAML IdP. If your configuration contains `add authentication samlAction` (SP) or `add authentication samlIdPProfile` (IdP), the precondition is met
- ✓If it is, update to a fixed build. For 14.1 that is 14.1-73.41 or later, for 13.1 it is 13.1-64.28 or later. FIPS: 14.1-73.41 FIPS or later; 13.1-FIPS and 13.1-NDcPP: 13.1-37.282 or later
- ✓★Appliances already updated for the 27 September batch (14.1-73.37 / 13.1-64.23 and so on) are in scope this time. 73.37 is earlier than 73.41, and 64.23 is earlier than 64.28
- ✓The action Citrix gives is to update. No workaround is listed. Until you can update, review which SAML virtual servers are exposed externally
- ✓CISA set the KEV due date to 7 October 2026. That deadline binds US federal agencies, but it is a useful schedule marker for everyone else too
What happened, with dates
27 September: Eight NetScaler vulnerabilities (CVE-2026-88771 to 88778) were published, and Citrix itself says exploitation of two of them (88771 and 88772) has been observed. The fixes were 14.1-73.37 and 13.1-64.23.
4 October: CVE-2026-88779 was published. The fixes are 14.1-73.41 and 13.1-64.28, newer builds.
So the 27 September update alone is not enough for this issue.
Preconditions and affected versions
- ▸Precondition (Citrix wording): NetScaler ADC or NetScaler Gateway is configured as a SAML SP or SAML IdP
- ▸Impact: memory overflow leading to denial of service. The CVSS v4.0 vector is `AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H`, meaning network-reachable, no authentication, no user interaction, with a high impact on availability only
- ▸Affected: 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, 14.1-FIPS before 14.1-73.41 FIPS, and 13.1-FIPS and 13.1-NDcPP before 13.1-37.282
- ▸Customer-managed NetScaler only. Citrix-managed cloud services and Adaptive Authentication are updated by Citrix
- ▸★Secure Private Access hybrid deployments that use NetScaler instances are also affected. Upgrade those NetScaler instances to the recommended builds
Check whether your appliance is SAML
Citrix tells customers to inspect the configuration for either of the following entries. SP and IdP both meet the precondition.
SAML SP : add authentication samlAction ...
SAML IdP : add authentication samlIdPProfile ...
# Example (this site's wording; Citrix only says to inspect the configuration)
grep -E "add authentication (samlAction|samlIdPProfile)" /nsconfig/ns.confIf neither line is present, the precondition for this CVE is not met. However, the 27 September issues are separate (88771 affects even the default configuration), so do not skip the update itself.
What is known and unknown about exploitation
CISA added it to KEV on 4 October (known ransomware campaign use is listed as "Unknown").
However, Citrix's bulletin for CVE-2026-88779 (CTX697174) does not say exploitation was observed. The statement that exploits were observed appears in the 27 September bulletin (CTX697096) for 88771 and 88772.
No details of how or how widely it is being used have been published. Treat the KEV listing alone as a reason to hurry, on the assumption that it is being used somewhere.
What could not be confirmed
- ▸NVD has not analysed it yet (status: Received), and the only CVSS shown is the CNA's v4.0 score of 8.7. NIST has no v3.1 rating yet. This article uses Citrix's v4.0 8.7 (HIGH)
- ▸The Citrix blog post linked from the bulletin returned an access-denied response and could not be read. This article relies on the bulletins themselves (CTX697174 and CTX697096) and on NVD, CVE.org and CISA
- ▸There is no source for how many NetScaler appliances actually run a SAML configuration
The 27 September batch (88771 to 88778) is not covered in a separate article here. Along with this update, check the CTX697096 preconditions (DTLS, HTTP, AAA and others) against your own configuration.
Three lines to share
- ▸NetScaler (formerly Citrix ADC/Gateway) has an unauthenticated DoS, CVE-2026-88779, and it is on the CISA KEV list. The precondition is a SAML SP / IdP configuration
- ▸★Appliances already moved to 14.1-73.37 / 13.1-64.23 on 27 September are affected too. The fix is 14.1-73.41 / 13.1-64.28 or later
- ▸Check your configuration for `add authentication samlAction` or `samlIdPProfile`, and update if present
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88779 (CTX697174: precondition, affected and fixed builds, how to check)↗
- Citrix: Security Bulletin for CVE-2026-88771 to 88778 (CTX697096: the 27 September batch and the observed-exploitation statement)↗
- CISA: Known Exploited Vulnerabilities Catalog (CVE-2026-88779, added 4 October 2026)↗
- NVD: CVE-2026-88779 (not yet analysed; only the CNA v4.0 score is shown)↗
- CVE.org: CVE-2026-88779 (published 4 October 2026)↗
- forsmile: an earlier NetScaler vulnerability article (July 2026)→
