Key Facts
- CVE: CVE-2026-88779
- CVSS: 8.7 High (CVSS 4.0)
- Exploited in the wild: Yes, reported by CISA KEV (added October 4, 2026)
- Fix available: Yes
- Last updated: October 5, 2026
What Is CVE-2026-88779?
CVE-2026-88779 is a Denial Of Service (Memory Overflow) vulnerability in Citrix NetScaler that lets an attacker with only network access overflow the appliance’s memory and force it offline, without needing a valid account. The vulnerability only applies when the appliance is configured as a SAML service provider or a SAML identity provider, a setup used for single sign-on authentication.
The vulnerability affects customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway appliances on the 14.1 and 13.1 branches, including FIPS and NDcPP builds. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are not affected, since Citrix updates those directly. Secure Private Access hybrid deployments that use NetScaler instances meet the same condition and need the same upgrade. Citrix has released fixed builds for every affected branch.
Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, since Citrix says these meet the precondition for this vulnerability. Appliances already updated under an earlier NetScaler security bulletin still need this additional update if they use SAML authentication.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-88779 | Denial Of Service (Memory Overflow) in Citrix NetScaler | 8.7 High (CVSS 4.0) | Yes |
Is CVE-2026-88779 Being Exploited?
CVE-2026-88779 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 4, 2026.
Timeline
- October 3, 2026: Citrix issued the initial publication of security bulletin CTX697174 for CVE-2026-88779 and, in a second changelog entry the same day, added a link to a companion NetScaler blog.
- October 3, 2026: NetScaler Console service release notes recorded support for identifying and remediating CVE-2026-88779, with identification requiring a version scan.
- October 3, 2026: Citrix published its explanatory blog on CVE-2026-88779, which carries a last-updated date of October 3, 2026 Pacific Daylight Time.
- October 4, 2026: CISA published an alert announcing it had added CVE-2026-88779, described as a Citrix NetScaler improper restriction of operations within the bounds of a memory buffer vulnerability, to the Known Exploited Vulnerabilities catalog.
What Is Citrix NetScaler?
Citrix NetScaler is a networking appliance that enterprises deploy at the network edge to handle application delivery, load balancing, and remote access, often managing authentication for users connecting to internal systems.
Which Citrix NetScaler Versions Are Affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Citrix NetScaler ADC and NetScaler Gateway (14.1) | before 14.1-73.41 | 14.1-73.41 and later releases |
| Citrix NetScaler ADC and NetScaler Gateway (13.1) | before 13.1-64.28 | 13.1-64.28 and later releases of 13.1 |
| Citrix NetScaler ADC 14.1-FIPS | before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later releases of 14.1-FIPS |
| Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP | before 13.1-37.282 | 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP |
Is Your Citrix NetScaler Affected?
- The appliance must be configured as a SAML service provider or a SAML identity provider for the vulnerability to apply.
- Secure Private Access hybrid deployments that use NetScaler instances meet the same precondition and require the same upgrade.
- The bulletin covers only customer-managed NetScaler ADC and NetScaler Gateway appliances; Citrix updates its own managed cloud services and Adaptive Authentication directly.
How to Fix CVE-2026-88779
Install the fixed NetScaler build for the branch in use, since the vulnerability depends on SAML configuration rather than the default setup. Until the upgrade can be scheduled, Citrix recommends enabling its Global Deny List signatures through NetScaler Console as an interim mitigation.
- Preserve logs, support bundles, and configuration snapshots from exposed appliances before making changes.
- Check NetScaler configurations for SAML service provider or identity provider entries to confirm exposure.
- Run Citrix’s indicator of compromise script through NetScaler Console to check for signs of compromise.
- Restrict network access to SAML-enabled Gateway and AAA virtual servers while remediation is underway.
- Install the fixed build for the branch in use on every exposed appliance.
- Enable Citrix’s Global Deny List signatures as an interim mitigation if upgrading isn’t immediate.
The vendor advisory has full details and any later changes.
Known Issues With the Update
Citrix warns that appliances already updated under an earlier NetScaler security bulletin still need these new builds if they meet the SAML precondition. Its indicator of compromise script, version 4, can report a false positive about suspicious nobody processes even when no compromise is found.
How to Check for Compromise
Citrix provides an indicator of compromise script delivered through NetScaler Console that administrators can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof. Administrators can also confirm the Global Deny List mitigation is active by checking that its rule counters and last hit time are above zero.
How watchTowr Is Helping Clients
The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
- Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.
Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-88779.
