What is CVE-2026-88779?
CVE-2026-88779 is a Memory Overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can disrupt the service these appliances provide. Citrix says repeatedly triggering the issue can leave the affected service unavailable, and its analysis found no impact on the integrity of customer data. The vulnerability only applies when the appliance is configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication.
An attacker who can reach the affected authentication service over the network can send traffic that overflows memory and crashes or hangs it, cutting off access for legitimate users without needing a valid account.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-88779 | Denial Of Service (Memory Overflow) in Citrix NetScaler | 8.7 High (CVSS 4.0) | Yes |
Is CVE-2026-88779 being exploited in the wild?
CVE-2026-88779 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 4, 2026.
How did CVE-2026-88779 come to light?
Citrix published security bulletin CTX697174 for CVE-2026-88779 on October 3, 2026, along with an explanatory blog post dated the same day. Citrix’s advisory credits Bishop Fox and watchTowr for working with the company to address the issue before publication.
How is watchTowr helping Citrix NetScaler customers?
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
- Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.
Our Rapid Reaction post covers CVE-2026-88779 in full.
What is Citrix NetScaler?
Citrix NetScaler is an application delivery controller and secure remote access gateway that organizations place at the edge of their networks. It manages traffic load balancing, user authentication, and VPN connections for employees and customers reaching internal applications.
Which Citrix NetScaler versions are affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.41 | 14.1-73.41 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.28 | 13.1-64.28 and later |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.282 | 13.1-37.282 and later |
- NetScaler ADC or NetScaler Gateway must be configured as a SAML service provider or a SAML identity provider for the vulnerability to apply.
- Secure Private Access hybrid deployments that use NetScaler instances also meet this precondition and need the same upgrade.
- Administrators can check their configuration for a SAML authentication action entry or a SAML identity provider profile entry to confirm exposure.
Deployments that use SAML authentication for Gateway or AAA (authentication, authorization, and auditing) virtual servers should upgrade first, since only those configurations meet the precondition for this vulnerability.
How do I fix CVE-2026-88779?
Citrix recommends upgrading every affected Citrix NetScaler ADC and NetScaler Gateway appliance to the fixed build for its branch. Until that upgrade happens, Citrix offers Global Deny List signatures as an interim mitigation, available to specific intermediate builds with Virtual patching enabled in NetScaler Console.
- Preserve logs, support bundles, and snapshots from each exposed appliance before making any changes.
- Check NetScaler configurations for a SAML authentication action or SAML identity provider profile entry to confirm exposure.
- Run the NetScaler Console indicator of compromise script to look for signs of compromise on affected appliances.
- Upgrade every affected NetScaler ADC and NetScaler Gateway appliance to the fixed build for its branch.
- Enable the Global Deny List mitigation with Virtual patching turned on if upgrading right away is not possible.
- Deploy a new instance instead of reusing an appliance if compromise is confirmed.
How do I check Citrix NetScaler for compromise?
Citrix provides an indicator of compromise script through NetScaler Console to check affected appliances for signs of compromise. Citrix notes that the latest script version can report a false positive about suspicious nobody processes even when it finds no compromise, so administrators should review results carefully and preserve evidence before applying the update.
Is CVE-2026-88779 related to earlier vulnerabilities?
Citrix states that appliances already upgraded under an earlier NetScaler security bulletin must be upgraded again to the newer builds that fix this vulnerability, if they meet the SAML precondition. The earlier fix does not address this issue.
What types of threat actors typically exploit this vulnerability?
Historically, ransomware gangs and APT groups exploit these vulnerabilities.
Have there been similar Citrix NetScaler vulnerabilities before?
Yes. These earlier Citrix NetScaler vulnerabilities were added to the CISA KEV catalog after exploitation in the wild:
| CVE | Description | Added to KEV |
|---|---|---|
| CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | September 27, 2026 |
| CVE-2026-88771 | Citrix NetScaler Improper Input Validation Vulnerability | September 27, 2026 |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | September 9, 2026 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | August 26, 2026 |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability | March 30, 2026 |
| CVE-2025-7775 | Citrix NetScaler Memory Overflow Vulnerability | August 26, 2025 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | July 10, 2025 |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | June 30, 2025 |
