Citrix Patches High-Severity NetScaler SAML Vulnerability (CVE-2026-88779)
Citrix has released emergency security updates to address CVE-2026-88779, a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable unauthenticated remote attackers to trigger persistent denial-of-service (DoS) conditions.
The flaw, rated 8.7 (CVSS v4), stems from improper memory buffer restrictions (CWE-119) and affects appliances configured for SAML authentication whether as a Service Provider (SP) or Identity Provider (IdP). Exploitation requires no authentication or user interaction, with low attack complexity, and primarily impacts availability by crashing devices or services.
Affected Configurations & Impact
The vulnerability applies only to NetScaler deployments with SAML authentication enabled, identifiable by the following configuration entries:
add authentication samlAction(SAML SP)add authentication samlIdPProfile(SAML IdP)
Successful exploitation could disrupt remote-access portals, identity flows, and applications reliant on NetScaler for authentication or traffic delivery. While Citrix confirms the flaw does not compromise data integrity, repeated attacks may cause operational outages, particularly for organizations using NetScaler for VPN, workforce access, or SSO services.
Vulnerable Versions & Fixes
Citrix has released patched versions for the following branches:
| Product Branch | Vulnerable Before | Fixed Release |
|---|---|---|
| NetScaler ADC & Gateway 14.1 | 14.1-73.41 | 14.1-73.41 or later |
| NetScaler ADC & Gateway 13.1 | 13.1-64.28 | 13.1-64.28 or later |
| NetScaler ADC 14.1-FIPS | 14.1-73.41 FIPS | 14.1-73.41 FIPS or later |
| NetScaler ADC 13.1-FIPS/NDcPP | 13.1-37.282 | 13.1-37.282 or later |
NetScaler Console users can detect impacted instances via the CVE Detection workflow and initiate upgrades directly.
Exploitation & Mitigation
Citrix reports targeted attacks against unpatched deployments. Security teams are advised to:
- Review appliance logs for crash events, unexpected reboots, SAML authentication failures, or anomalous
nsaaadservice behavior. - Monitor firewall telemetry and identity-provider logs for signs of exploitation.
The vulnerability was addressed with contributions from Bishop Fox and watchTowr. Organizations using SAML-enabled NetScaler appliances for federated authentication should prioritize patching externally exposed instances.
Source: https://gbhackers.com/citrix-netscaler-saml-vulnerability/
Citrix TPRM report: https://www.rankiteo.com/company/citrix
"id": "cit1791181418",
"linkid": "citrix",
"type": "Vulnerability",
"date": "10/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Organizations using NetScaler '
'ADC and NetScaler Gateway with '
'SAML authentication enabled',
'industry': 'Technology/Software',
'name': 'Citrix',
'type': 'Vendor'}],
'attack_vector': 'Remote',
'description': 'Citrix has released emergency security updates to address '
'CVE-2026-88779, a high-severity memory overflow vulnerability '
'in NetScaler ADC and NetScaler Gateway that could enable '
'unauthenticated remote attackers to trigger persistent '
'denial-of-service (DoS) conditions. The flaw affects '
'appliances configured for SAML authentication as a Service '
'Provider (SP) or Identity Provider (IdP).',
'impact': {'downtime': 'Persistent DoS conditions, operational outages',
'operational_impact': 'Disruption of remote-access portals, '
'identity flows, and applications reliant on '
'NetScaler for authentication or traffic '
'delivery',
'systems_affected': 'NetScaler ADC and NetScaler Gateway with SAML '
'authentication enabled'},
'post_incident_analysis': {'corrective_actions': 'Apply security patches, '
'review and update SAML '
'configurations, enhance '
'monitoring for exploitation '
'attempts',
'root_causes': 'Improper memory buffer '
'restrictions (CWE-119) in SAML '
'authentication configurations'},
'recommendations': 'Prioritize patching externally exposed instances, review '
'appliance logs for signs of exploitation, and monitor '
'identity-provider logs.',
'references': [{'source': 'Citrix Security Bulletin'},
{'source': 'Bishop Fox'},
{'source': 'watchTowr'}],
'response': {'containment_measures': 'Patch deployment, log review for crash '
'events or anomalous behavior',
'enhanced_monitoring': 'Monitor firewall telemetry and '
'identity-provider logs for signs of '
'exploitation',
'remediation_measures': 'Apply security updates to vulnerable '
'NetScaler versions',
'third_party_assistance': 'Bishop Fox, watchTowr'},
'title': 'Citrix Patches High-Severity NetScaler SAML Vulnerability '
'(CVE-2026-88779)',
'type': 'Vulnerability',
'vulnerability_exploited': 'CVE-2026-88779 (Memory Overflow - CWE-119)'}