NetScaler CVE-2026-88779: Zero-Day Can Knock SAML Logins Offline
Citrix has patched an actively exploited memory overflow in NetScaler ADC and Gateway that causes denial of service on appliances configured for SAML. Because those appliances sit in the authentication path, an outage can lock out remote access for a whole organisation.
Key Takeaways
- CVE-2026-88779 (CVSS 8.7) is a memory overflow in Citrix NetScaler ADC and Gateway that was exploited as a zero-day in targeted attacks.
- Only appliances configured as a SAML service provider or SAML identity provider are exposed, and the impact is denial of service.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog on 4 October 2026, with a federal patch deadline of 7 October 2026.
- Upgrade to a fixed build, and audit your NetScaler configuration to find out whether you are in the affected population.
What happened
Citrix has released fixes for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway. The Hacker News reports that it was exploited as a zero-day in targeted attacks, and that active exploitation was seen against unpatched systems. The CVSS score is 8.7. Bishop Fox and watchTowr are credited as reporters.
The reported impact is denial of service under specific deployment conditions. Repeated triggering can cause prolonged unavailability. No compromise of customer data integrity has been identified so far.
Who is exposed
This is not a flaw in every NetScaler. The vulnerable condition requires the appliance to be configured in one of two SAML roles:
- As a SAML service provider (SP), shown by an
add authentication samlActionentry in the configuration. - As a SAML identity provider (IdP), shown by an
add authentication samlIdPProfileentry in the configuration.
If neither entry exists, the reported exploitation conditions are not met. You should still patch, since configurations change and the fixed builds are the supported state.
Fixed versions
The reported fixed builds are:
- NetScaler ADC and Gateway 14.1-73.41 and later.
- NetScaler ADC and Gateway 13.1-64.28 and later in the 13.1 branch.
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later.
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later.
Why a denial of service here still matters
A denial of service on a perimeter appliance is easy to underrate. NetScaler Gateway and ADC often terminate remote access and single sign-on for the whole workforce. When the SAML path goes down, users lose access to the applications behind it. Operations teams under pressure may then reach for a temporary bypass, and that is when security controls get weakened.
The "targeted attacks" wording is also a reason to act promptly. Exploitation before a patch existed means some organisations were chosen deliberately. CISA's addition of the flaw to the Known Exploited Vulnerabilities catalog on 4 October 2026, with a federal agency deadline of 7 October 2026, signals the same urgency. Private-sector defenders should treat that deadline as a reasonable benchmark.
What to do now
- 1Inventory every NetScaler ADC and Gateway instance, including FIPS and NDcPP builds and any appliance outside your normal change process.
- 2Check configurations for
samlActionandsamlIdPProfileentries to find the exposed population. - 3Upgrade to a fixed build. Where you cannot patch immediately, prioritise the appliances that serve SAML for critical applications.
- 4Review logs and monitoring for unexplained appliance crashes, restarts or authentication outages, which may point to exploitation attempts.
- 5Make sure you have a tested fallback for authentication outages that does not bypass your access controls.
The sources reviewed do not describe how to confirm past exploitation on an appliance. If you suspect it, preserve logs and evidence before rebooting or rebuilding, and treat the investigation as an incident.
Frequently Asked Questions
What is CVE-2026-88779?
It is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, rated CVSS 8.7. It was exploited as a zero-day in targeted attacks, and it can cause denial of service on SAML deployments.
Which NetScaler configurations are affected?
Appliances configured as a SAML service provider (an `add authentication samlAction` entry) or as a SAML identity provider (an `add authentication samlIdPProfile` entry) meet the conditions for exploitation.
Does this vulnerability expose customer data?
The reported impact is denial of service, with prolonged unavailability possible if the flaw is triggered repeatedly. No compromise of customer data integrity has been identified.