Skip to content
>_ITDITDWeb Security Platform

Threat feed

CVE-2026-88779 — Memory flaw in NetScaler ADC/Gateway SAML configurations (DoS, exploited): explainer and fix

CVE-2026-88779: memory flaw (CWE-119) in NetScaler ADC/Gateway configured as a SAML SP or IdP, letting an unauthenticated attacker cause denial of service. Fixed 3 Oct 2026 (14.1-73.41, 13.1-64.28 and others); in CISA KEV since 4 Oct. The 27 Sep builds do not fix it.

Published 2026-10-05 Updated 2026-10-05 Last verified 2026-10-05 10 min read

This is a rapid explainer for a vulnerability that is being actively exploited (listed in CISA KEV). It covers what happens, who is affected and how to respond — from the defender's side, with no reproduction steps.

Advisory summary
CVE
CVE-2026-88779 (vendor bulletin CTX697174)
Severity
Vendor: High / CVSS v4.0 8.7 (NVD has not analysed it yet; no v3.1 score)
Type
Memory flaw (CWE-119: operations outside the bounds of a memory buffer)
Impact
Vendor classification: denial of service (DoS). Possible code execution is under investigation by researchers
Preconditions
No authentication, no user interaction. Appliances configured as a SAML SP or SAML IdP
Affected
NetScaler ADC / NetScaler Gateway 14.1 and 13.1, plus FIPS/NDcPP builds, before the fixed builds
Fix
14.1-73.41 / 13.1-64.28 and others, released 3 October 2026 (the 27 September builds do not fix it)
Exploitation
In CISA KEV (added 4 October 2026, remediation due 7 October), flagged as requiring forensic triage
SAML
Affects appliances configured as SP or IdP
No auth
What an attacker needs
7 days
From the 88771/88772 KEV listing (27 Sep) to this one (4 Oct)
0.3%
EPSS on 4 Oct — at odds with KEV

How dangerous is it to wait?

The vendor says it has observed targeted attacks on unmitigated NetScaler deployments that can lead to DoS. NetScaler Gateway is used as the VPN and remote-access entry point, so when it goes down, remote work goes down with it. This product has had a run of exploited flaws since September: CVE-2026-19490 (authentication bypass), then CVE-2026-88771/88772 (code execution). Assume attackers are working on this product continuously.

What kind of flaw is it?

SAML is a way to sign users in by passing along the result of a login done in another system. NetScaler can act as the side that accepts that result (SP) or the side that issues it (IdP). According to the vendor's bulletin, appliances with SAML processing turned on had a flaw that lets operations run outside the bounds of a memory buffer (CWE-119). This site does not describe how it is exploited.

The vendor classes it as denial of service, and the CVSS v4.0 vector says "no authentication, availability impact only". The vendor says it has not identified an impact on the integrity of customer data. Researchers, however, have reported observations suggesting it may have been used for code execution rather than only DoS. That is under investigation and not confirmed.

The vendor's position (bulletin and blog)

  • Classified as denial of service caused by memory corruption
  • Targeted attacks on unmitigated deployments observed
  • No impact on customer data integrity identified

Researchers' observations (as reported)

  • Reports of malicious programs running even on patched honeypots
  • Whether that is code execution through this flaw is under investigation
  • CVE-2026-8452, another SAML-configuration flaw, was published as DoS and later analysed as leading to code execution

Before 14.1-73.37: neither 88771/88772 nor 88779 fixed

→ update, and also check for intrusion

14.1-73.37 (27 Sep fix): 88779 not fixed

→ if you use SAML, update again

14.1-73.41 or later (3 Oct fix): outside this bulletin

→ on 13.1, the equivalent is 13.1-64.28 or later

The 27 September builds do not fix CVE-2026-88779. Appliances using SAML need a build from 3 October or later.

Who is affected

Release lineAffected buildsFixed builds
NetScaler ADC / Gateway 14.1before 14.1-73.4114.1-73.41 and later
NetScaler ADC / Gateway 13.1before 13.1-64.2813.1-64.28 and later
NetScaler ADC 14.1-FIPSbefore 14.1-73.41 FIPS14.1-73.41 FIPS and later
NetScaler ADC 13.1-FIPS / 13.1-NDcPPbefore 13.1-37.28213.1-37.282 and later
  • The precondition is a SAML SP configuration (add authentication samlAction) or a SAML IdP configuration (add authentication samlIdPProfile).
  • Secure Private Access hybrid deployments using NetScaler are affected; customers update those NetScaler instances.
  • The vendor updates Citrix-managed cloud services and Adaptive Authentication.
  • The bulletin lists only the supported lines above. If you run an end-of-life line, move to a supported one.

What to do

1

Check whether you use SAML

Look for add authentication samlAction (SAML SP) or add authentication samlIdPProfile (SAML IdP) in the NetScaler configuration. Either one puts the appliance in scope. If you have several, check each one (security inventory checklist).

2

Update to the fixed build (first priority)

Move to your line's fixed build or later (14.1-73.41 / 13.1-64.28 / 14.1-73.41 FIPS / 13.1-37.282). Appliances on the 27 September builds (14.1-73.37 and so on) are included. After updating, confirm the build number actually running. This bulletin (CTX697174) does not list extra post-update steps such as ending sessions.

3

If you cannot update right away, cover the gap

The bulletin lists no workaround. According to press reports, the vendor's blog points to NetScaler's Global Deny List (a feature that blocks traffic from known attack sources) as a stopgap until you update. It does not replace the update.

4

Check for crashes and intrusion

CISA flags this CVE for forensic triage. First, check whether the appliance crashed or restarted unexpectedly before the update, and contact vendor support if it did. Appliances that got the 88771/88772 fix after 27 September should be checked with the vendor's steps for a suspected compromise (CTX694799) and the checks listed in JPCERT/CC's alert (suspicious web-server configuration changes, unfamiliar files, suspicious permission changes and so on).

5

If you find signs of intrusion, don't stop at 'patched'

An update closes the hole; it does not remove a backdoor already in place or credentials already stolen. Rebuild the appliance, replace the certificates, keys and passwords stored on it, and review accounts that signed in through it. The full process is in the vulnerability remediation playbook.

The exploited flaws just before this one: CVE-2026-88771 / 88772

On 27 September 2026 the vendor disclosed eight vulnerabilities and confirmed exploitation of two. CISA added both to KEV the same day.

  • CVE-2026-88771: improper input validation (CWE-20) letting an unauthenticated attacker run arbitrary commands. Per JPCERT/CC, all configurations including the default are affected
  • CVE-2026-88772: memory flaw (CWE-119) leading to code execution or DoS. Affects configurations with DTLS enabled, which is on by default for Gateway VPN virtual servers
  • Fixed in 14.1-73.37, 13.1-64.23 and others. JPCERT/CC says attack attempts against NetScaler in Japan were observed from 24 September
  • A threat-intelligence team's report, cited by JPCERT/CC, describes post-exploitation activity after 88772, such as planting web shells to keep access

Before that, on 9 September, CVE-2026-19490 (authentication bypass in Gateway and AAA virtual server configurations) was also added to KEV.

This site's view: on a VPN appliance, treat 'only DoS' as top priority anyway

The vendor classes this flaw as DoS, and EPSS (the estimated chance of exploitation over the next 30 days) is a low 0.3%. We still think it deserves the same priority as a code-execution flaw, for three reasons.

First, NetScaler Gateway is the way in from outside, so an outage is costly in itself. Second, CVE-2026-8452, another SAML-configuration flaw, was published as DoS and later analysed as leading to code execution — classifications can change. Third, this product has had four exploited flaws in about a month, and appliances need updating again right after being updated.

Owning a VPN appliance assumes you can apply emergency updates several times a month. If you cannot, the question becomes whether to keep the appliance at all (defending VPN appliances).

Sources

FAQ

QWhat does CVE-2026-88779 allow?
A

According to the vendor's (Cloud Software Group's) bulletin, it is a memory-handling flaw (CWE-119) in NetScaler ADC/Gateway that leads to denial of service. The CVSS v4.0 vector says no authentication or user interaction is needed and only availability is affected. CISA added it to KEV on 4 October 2026 after confirming active exploitation.

QWhich appliances are affected?
A

The bulletin's precondition is that NetScaler ADC or Gateway is configured as a SAML SP (service provider) or SAML IdP (identity provider) — that is, the configuration contains add authentication samlAction or add authentication samlIdPProfile. Affected builds: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282 for 13.1 FIPS/NDcPP.

QI patched CVE-2026-88771/88772 in late September. Am I covered?
A

No. The builds that fixed 88771/88772 (14.1-73.37, 13.1-64.23 and so on) are older than this fix (14.1-73.41, 13.1-64.28 and so on), so CVE-2026-88779 is still present. Update again.

QIf it is only DoS, can it wait?
A

No. NetScaler Gateway is the remote-access entry point, so an outage stops remote work across the organisation. Researchers have also reported observations suggesting it may have been used for code execution, not just DoS; that is still under investigation (the vendor classes it as DoS). Another SAML-configuration flaw, CVE-2026-8452, was published as DoS and later analysed as leading to code execution under some conditions.

QWhat if I use Citrix-managed cloud services?
A

The bulletin covers customer-managed NetScaler. The vendor updates Citrix-managed cloud services and Adaptive Authentication. Secure Private Access hybrid deployments that use NetScaler are affected, though, and customers must update those NetScaler instances themselves.