Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Citrix NetScaler Denial Of Service (Memory Overflow) (CVE-2026-88779)

CVE-2026-88779 is a Denial Of Service (Memory Overflow) in Citrix NetScaler that can make appliances configured for SAML authentication stop responding. Apply the fixed build for the affected branch, or use Citrix's interim mitigation.

Key Facts

  • CVE: CVE-2026-88779
  • CVSS: 8.7 High (CVSS 4.0)
  • Exploited in the wild: Yes, reported by CISA KEV (added October 4, 2026)
  • Fix available: Yes
  • Last updated: October 5, 2026

What Is CVE-2026-88779?

CVE-2026-88779 is a Denial Of Service (Memory Overflow) vulnerability in Citrix NetScaler that lets an attacker with only network access overflow the appliance’s memory and force it offline, without needing a valid account. The vulnerability only applies when the appliance is configured as a SAML service provider or a SAML identity provider, a setup used for single sign-on authentication.

The vulnerability affects customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway appliances on the 14.1 and 13.1 branches, including FIPS and NDcPP builds. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are not affected, since Citrix updates those directly. Secure Private Access hybrid deployments that use NetScaler instances meet the same condition and need the same upgrade. Citrix has released fixed builds for every affected branch.

Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, since Citrix says these meet the precondition for this vulnerability. Appliances already updated under an earlier NetScaler security bulletin still need this additional update if they use SAML authentication.

CVEDescriptionCVSSExploited in the wild
CVE-2026-88779Denial Of Service (Memory Overflow) in Citrix NetScaler8.7 High (CVSS 4.0)Yes

Is CVE-2026-88779 Being Exploited?

CVE-2026-88779 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 4, 2026.

Timeline

  • October 3, 2026: Citrix issued the initial publication of security bulletin CTX697174 for CVE-2026-88779 and, in a second changelog entry the same day, added a link to a companion NetScaler blog.
  • October 3, 2026: NetScaler Console service release notes recorded support for identifying and remediating CVE-2026-88779, with identification requiring a version scan.
  • October 3, 2026: Citrix published its explanatory blog on CVE-2026-88779, which carries a last-updated date of October 3, 2026 Pacific Daylight Time.
  • October 4, 2026: CISA published an alert announcing it had added CVE-2026-88779, described as a Citrix NetScaler improper restriction of operations within the bounds of a memory buffer vulnerability, to the Known Exploited Vulnerabilities catalog.

What Is Citrix NetScaler?

Citrix NetScaler is a networking appliance that enterprises deploy at the network edge to handle application delivery, load balancing, and remote access, often managing authentication for users connecting to internal systems.

Which Citrix NetScaler Versions Are Affected?

ProductAffected VersionsFixed Version
Citrix NetScaler ADC and NetScaler Gateway (14.1)before 14.1-73.4114.1-73.41 and later releases
Citrix NetScaler ADC and NetScaler Gateway (13.1)before 13.1-64.2813.1-64.28 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPSbefore 14.1-73.41 FIPS14.1-73.41 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPPbefore 13.1-37.28213.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Is Your Citrix NetScaler Affected?

  • The appliance must be configured as a SAML service provider or a SAML identity provider for the vulnerability to apply.
  • Secure Private Access hybrid deployments that use NetScaler instances meet the same precondition and require the same upgrade.
  • The bulletin covers only customer-managed NetScaler ADC and NetScaler Gateway appliances; Citrix updates its own managed cloud services and Adaptive Authentication directly.

How to Fix CVE-2026-88779

Install the fixed NetScaler build for the branch in use, since the vulnerability depends on SAML configuration rather than the default setup. Until the upgrade can be scheduled, Citrix recommends enabling its Global Deny List signatures through NetScaler Console as an interim mitigation.

  1. Preserve logs, support bundles, and configuration snapshots from exposed appliances before making changes.
  2. Check NetScaler configurations for SAML service provider or identity provider entries to confirm exposure.
  3. Run Citrix’s indicator of compromise script through NetScaler Console to check for signs of compromise.
  4. Restrict network access to SAML-enabled Gateway and AAA virtual servers while remediation is underway.
  5. Install the fixed build for the branch in use on every exposed appliance.
  6. Enable Citrix’s Global Deny List signatures as an interim mitigation if upgrading isn’t immediate.

The vendor advisory has full details and any later changes.

Known Issues With the Update

Citrix warns that appliances already updated under an earlier NetScaler security bulletin still need these new builds if they meet the SAML precondition. Its indicator of compromise script, version 4, can report a false positive about suspicious nobody processes even when no compromise is found.

How to Check for Compromise

Citrix provides an indicator of compromise script delivered through NetScaler Console that administrators can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof. Administrators can also confirm the Global Deny List mitigation is active by checking that its rule counters and last hit time are above zero.

How watchTowr Is Helping Clients

The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.

  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
  • Active Defense released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.

Request a demo to see how Rapid Reaction identifies exposure to emerging threats like CVE-2026-88779.


If you are a watchTowr client

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

On this page
Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.