Threat feed
CVE-2026-88779 — Memory flaw in NetScaler ADC/Gateway SAML configurations (DoS, exploited): explainer and fix
CVE-2026-88779: memory flaw (CWE-119) in NetScaler ADC/Gateway configured as a SAML SP or IdP, letting an unauthenticated attacker cause denial of service. Fixed 3 Oct 2026 (14.1-73.41, 13.1-64.28 and others); in CISA KEV since 4 Oct. The 27 Sep builds do not fix it.
This is a rapid explainer for a vulnerability that is being actively exploited (listed in CISA KEV). It covers what happens, who is affected and how to respond — from the defender's side, with no reproduction steps.
- CVE
- CVE-2026-88779 (vendor bulletin CTX697174)
- Severity
- Vendor: High / CVSS v4.0 8.7 (NVD has not analysed it yet; no v3.1 score)
- Type
- Memory flaw (CWE-119: operations outside the bounds of a memory buffer)
- Impact
- Vendor classification: denial of service (DoS). Possible code execution is under investigation by researchers
- Preconditions
- No authentication, no user interaction. Appliances configured as a SAML SP or SAML IdP
- Affected
- NetScaler ADC / NetScaler Gateway 14.1 and 13.1, plus FIPS/NDcPP builds, before the fixed builds
- Fix
- 14.1-73.41 / 13.1-64.28 and others, released 3 October 2026 (the 27 September builds do not fix it)
- Exploitation
- In CISA KEV (added 4 October 2026, remediation due 7 October), flagged as requiring forensic triage
How dangerous is it to wait?
The vendor says it has observed targeted attacks on unmitigated NetScaler deployments that can lead to DoS. NetScaler Gateway is used as the VPN and remote-access entry point, so when it goes down, remote work goes down with it. This product has had a run of exploited flaws since September: CVE-2026-19490 (authentication bypass), then CVE-2026-88771/88772 (code execution). Assume attackers are working on this product continuously.
What kind of flaw is it?
SAML is a way to sign users in by passing along the result of a login done in another system. NetScaler can act as the side that accepts that result (SP) or the side that issues it (IdP). According to the vendor's bulletin, appliances with SAML processing turned on had a flaw that lets operations run outside the bounds of a memory buffer (CWE-119). This site does not describe how it is exploited.
The vendor classes it as denial of service, and the CVSS v4.0 vector says "no authentication, availability impact only". The vendor says it has not identified an impact on the integrity of customer data. Researchers, however, have reported observations suggesting it may have been used for code execution rather than only DoS. That is under investigation and not confirmed.
The vendor's position (bulletin and blog)
- Classified as denial of service caused by memory corruption
- Targeted attacks on unmitigated deployments observed
- No impact on customer data integrity identified
Researchers' observations (as reported)
- Reports of malicious programs running even on patched honeypots
- Whether that is code execution through this flaw is under investigation
- CVE-2026-8452, another SAML-configuration flaw, was published as DoS and later analysed as leading to code execution
Before 14.1-73.37: neither 88771/88772 nor 88779 fixed
→ update, and also check for intrusion
14.1-73.37 (27 Sep fix): 88779 not fixed
→ if you use SAML, update again
14.1-73.41 or later (3 Oct fix): outside this bulletin
→ on 13.1, the equivalent is 13.1-64.28 or later
Who is affected
| Release line | Affected builds | Fixed builds |
|---|---|---|
| NetScaler ADC / Gateway 14.1 | before 14.1-73.41 | 14.1-73.41 and later |
| NetScaler ADC / Gateway 13.1 | before 13.1-64.28 | 13.1-64.28 and later |
| NetScaler ADC 14.1-FIPS | before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later |
| NetScaler ADC 13.1-FIPS / 13.1-NDcPP | before 13.1-37.282 | 13.1-37.282 and later |
- The precondition is a SAML SP configuration (
add authentication samlAction) or a SAML IdP configuration (add authentication samlIdPProfile). - Secure Private Access hybrid deployments using NetScaler are affected; customers update those NetScaler instances.
- The vendor updates Citrix-managed cloud services and Adaptive Authentication.
- The bulletin lists only the supported lines above. If you run an end-of-life line, move to a supported one.
What to do
Check whether you use SAML
Look for add authentication samlAction (SAML SP) or add authentication samlIdPProfile (SAML IdP) in the NetScaler configuration. Either one puts the appliance in scope. If you have several, check each one (security inventory checklist).
Update to the fixed build (first priority)
Move to your line's fixed build or later (14.1-73.41 / 13.1-64.28 / 14.1-73.41 FIPS / 13.1-37.282). Appliances on the 27 September builds (14.1-73.37 and so on) are included. After updating, confirm the build number actually running. This bulletin (CTX697174) does not list extra post-update steps such as ending sessions.
If you cannot update right away, cover the gap
The bulletin lists no workaround. According to press reports, the vendor's blog points to NetScaler's Global Deny List (a feature that blocks traffic from known attack sources) as a stopgap until you update. It does not replace the update.
Check for crashes and intrusion
CISA flags this CVE for forensic triage. First, check whether the appliance crashed or restarted unexpectedly before the update, and contact vendor support if it did. Appliances that got the 88771/88772 fix after 27 September should be checked with the vendor's steps for a suspected compromise (CTX694799) and the checks listed in JPCERT/CC's alert (suspicious web-server configuration changes, unfamiliar files, suspicious permission changes and so on).
If you find signs of intrusion, don't stop at 'patched'
An update closes the hole; it does not remove a backdoor already in place or credentials already stolen. Rebuild the appliance, replace the certificates, keys and passwords stored on it, and review accounts that signed in through it. The full process is in the vulnerability remediation playbook.
The exploited flaws just before this one: CVE-2026-88771 / 88772
On 27 September 2026 the vendor disclosed eight vulnerabilities and confirmed exploitation of two. CISA added both to KEV the same day.
- CVE-2026-88771: improper input validation (CWE-20) letting an unauthenticated attacker run arbitrary commands. Per JPCERT/CC, all configurations including the default are affected
- CVE-2026-88772: memory flaw (CWE-119) leading to code execution or DoS. Affects configurations with DTLS enabled, which is on by default for Gateway VPN virtual servers
- Fixed in 14.1-73.37, 13.1-64.23 and others. JPCERT/CC says attack attempts against NetScaler in Japan were observed from 24 September
- A threat-intelligence team's report, cited by JPCERT/CC, describes post-exploitation activity after 88772, such as planting web shells to keep access
Before that, on 9 September, CVE-2026-19490 (authentication bypass in Gateway and AAA virtual server configurations) was also added to KEV.
This site's view: on a VPN appliance, treat 'only DoS' as top priority anyway
The vendor classes this flaw as DoS, and EPSS (the estimated chance of exploitation over the next 30 days) is a low 0.3%. We still think it deserves the same priority as a code-execution flaw, for three reasons.
First, NetScaler Gateway is the way in from outside, so an outage is costly in itself. Second, CVE-2026-8452, another SAML-configuration flaw, was published as DoS and later analysed as leading to code execution — classifications can change. Third, this product has had four exploited flaws in about a month, and appliances need updating again right after being updated.
Owning a VPN appliance assumes you can apply emergency updates several times a month. If you cannot, the question becomes whether to keep the appliance at all (defending VPN appliances).
Sources
- Cloud Software Group — CTX697174: Security Bulletin for CVE-2026-88779 (published 3 October 2026, US Pacific time; preconditions, affected and fixed builds, CVSS v4.0 8.7)
- NVD — CVE-2026-88779 (status "Received", not yet analysed, as of 5 October; CWE-119)
- CISA KEV — Known Exploited Vulnerabilities Catalog (added 4 October 2026, due 7 October, forensic triage required)
- JPCERT/CC — Alert on CVE-2026-88771, CVE-2026-88772 and others (Japanese; published 28 September, updated 2 October; no alert on CVE-2026-88779 as of 5 October) / Alert on CVE-2026-8452 (Japanese)
- IPA — NetScaler ADC and NetScaler Gateway vulnerabilities (CVE-2026-88771, CVE-2026-88772 and others) (Japanese)
- Press — BleepingComputer (the vendor blog's statements and researchers' observations on possible code execution; this article uses only the facts and defender-side checks)
- FIRST — EPSS (0.0028 on 4 October 2026)
Read next
- Practice: Defending VPN appliances / The vulnerability remediation playbook
- Deciding: Prioritising with CVSS, EPSS and KEV
- Terms: What is a backdoor? / What is an IOC? / What is CVSS?
FAQ
QWhat does CVE-2026-88779 allow?
According to the vendor's (Cloud Software Group's) bulletin, it is a memory-handling flaw (CWE-119) in NetScaler ADC/Gateway that leads to denial of service. The CVSS v4.0 vector says no authentication or user interaction is needed and only availability is affected. CISA added it to KEV on 4 October 2026 after confirming active exploitation.
QWhich appliances are affected?
The bulletin's precondition is that NetScaler ADC or Gateway is configured as a SAML SP (service provider) or SAML IdP (identity provider) — that is, the configuration contains add authentication samlAction or add authentication samlIdPProfile. Affected builds: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282 for 13.1 FIPS/NDcPP.
QI patched CVE-2026-88771/88772 in late September. Am I covered?
No. The builds that fixed 88771/88772 (14.1-73.37, 13.1-64.23 and so on) are older than this fix (14.1-73.41, 13.1-64.28 and so on), so CVE-2026-88779 is still present. Update again.
QIf it is only DoS, can it wait?
No. NetScaler Gateway is the remote-access entry point, so an outage stops remote work across the organisation. Researchers have also reported observations suggesting it may have been used for code execution, not just DoS; that is still under investigation (the vendor classes it as DoS). Another SAML-configuration flaw, CVE-2026-8452, was published as DoS and later analysed as leading to code execution under some conditions.
QWhat if I use Citrix-managed cloud services?
The bulletin covers customer-managed NetScaler. The vendor updates Citrix-managed cloud services and Adaptive Authentication. Secure Private Access hybrid deployments that use NetScaler are affected, though, and customers must update those NetScaler instances themselves.