Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Updated Oct 5, 2026

Frequently Asked Questions About the Citrix NetScaler Denial Of Service (Memory Overflow) (CVE-2026-88779)

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause a denial of service when SAML authentication is configured. This FAQ is updated as details emerge.

Status

CVE

CVE-2026-88779

CVSS

8.7 (v4.0)

Exploitation

In The Wild

CISA KEV

Listed

Vendor patch

Available

Questions

Updates

Key takeaways

What is CVE-2026-88779?

CVE-2026-88779 is a Memory Overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can disrupt the service these appliances provide. Citrix says repeatedly triggering the issue can leave the affected service unavailable, and its analysis found no impact on the integrity of customer data. The vulnerability only applies when the appliance is configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication.

An attacker who can reach the affected authentication service over the network can send traffic that overflows memory and crashes or hangs it, cutting off access for legitimate users without needing a valid account.

CVEDescriptionCVSSExploited in the wild
CVE-2026-88779Denial Of Service (Memory Overflow) in Citrix NetScaler8.7 High (CVSS 4.0)Yes

Is CVE-2026-88779 being exploited in the wild?

CVE-2026-88779 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 4, 2026.

How did CVE-2026-88779 come to light?

Citrix published security bulletin CTX697174 for CVE-2026-88779 on October 3, 2026, along with an explanatory blog post dated the same day. Citrix’s advisory credits Bishop Fox and watchTowr for working with the company to address the issue before publication.

How is watchTowr helping Citrix NetScaler customers?

  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
  • Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.

Our Rapid Reaction post covers CVE-2026-88779 in full.

What is Citrix NetScaler?

Citrix NetScaler is an application delivery controller and secure remote access gateway that organizations place at the edge of their networks. It manages traffic load balancing, user authentication, and VPN connections for employees and customers reaching internal applications.

Which Citrix NetScaler versions are affected?

ProductAffected VersionsFixed Version
NetScaler ADC and NetScaler Gateway 14.1Before 14.1-73.4114.1-73.41 and later
NetScaler ADC and NetScaler Gateway 13.1Before 13.1-64.2813.1-64.28 and later
NetScaler ADC 14.1-FIPSBefore 14.1-73.41 FIPS14.1-73.41 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPPBefore 13.1-37.28213.1-37.282 and later
  • NetScaler ADC or NetScaler Gateway must be configured as a SAML service provider or a SAML identity provider for the vulnerability to apply.
  • Secure Private Access hybrid deployments that use NetScaler instances also meet this precondition and need the same upgrade.
  • Administrators can check their configuration for a SAML authentication action entry or a SAML identity provider profile entry to confirm exposure.

Deployments that use SAML authentication for Gateway or AAA (authentication, authorization, and auditing) virtual servers should upgrade first, since only those configurations meet the precondition for this vulnerability.

How do I fix CVE-2026-88779?

Citrix recommends upgrading every affected Citrix NetScaler ADC and NetScaler Gateway appliance to the fixed build for its branch. Until that upgrade happens, Citrix offers Global Deny List signatures as an interim mitigation, available to specific intermediate builds with Virtual patching enabled in NetScaler Console.

  1. Preserve logs, support bundles, and snapshots from each exposed appliance before making any changes.
  2. Check NetScaler configurations for a SAML authentication action or SAML identity provider profile entry to confirm exposure.
  3. Run the NetScaler Console indicator of compromise script to look for signs of compromise on affected appliances.
  4. Upgrade every affected NetScaler ADC and NetScaler Gateway appliance to the fixed build for its branch.
  5. Enable the Global Deny List mitigation with Virtual patching turned on if upgrading right away is not possible.
  6. Deploy a new instance instead of reusing an appliance if compromise is confirmed.

How do I check Citrix NetScaler for compromise?

Citrix provides an indicator of compromise script through NetScaler Console to check affected appliances for signs of compromise. Citrix notes that the latest script version can report a false positive about suspicious nobody processes even when it finds no compromise, so administrators should review results carefully and preserve evidence before applying the update.

Is CVE-2026-88779 related to earlier vulnerabilities?

Citrix states that appliances already upgraded under an earlier NetScaler security bulletin must be upgraded again to the newer builds that fix this vulnerability, if they meet the SAML precondition. The earlier fix does not address this issue.

What types of threat actors typically exploit this vulnerability?

Historically, ransomware gangs and APT groups exploit these vulnerabilities.

Have there been similar Citrix NetScaler vulnerabilities before?

Yes. These earlier Citrix NetScaler vulnerabilities were added to the CISA KEV catalog after exploitation in the wild:

CVEDescriptionAdded to KEV
CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilitySeptember 27, 2026
CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilitySeptember 27, 2026
CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilitySeptember 9, 2026
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityAugust 26, 2026
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read VulnerabilityMarch 30, 2026
CVE-2025-7775Citrix NetScaler Memory Overflow VulnerabilityAugust 26, 2025
CVE-2025-5777Citrix NetScaler ADC and Gateway Out-of-Bounds Read VulnerabilityJuly 10, 2025
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow VulnerabilityJune 30, 2025

If you are a watchTowr client

Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act. Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied. Contact your watchTowr team with any questions.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.