Citrix patches exploited NetScaler SAML flaw CVE-2026-88779
Citrix patched exploited NetScaler ADC and Gateway flaw CVE-2026-88779, a CVSS 8.7 SAML memory overflow linked to denial of service, as CISA set an October 7 deadline.
Citrix issued emergency updates for CVE-2026-88779, a CVSS 8.7 memory-buffer overflow in customer-managed NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, or with SAML Gateway or AAA. Citrix said targeted attacks caused denial of service on unmitigated appliances and that data integrity was not affected, and it shipped fixes including 14.1-73.41 and 13.1-64.28 plus FIPS builds, deny-list signatures, and an indicator script, crediting watchTowr and Bishop Fox. CISA added the flaw to the Known Exploited Vulnerabilities catalog on October 4, 2026, and ordered U.S. federal agencies to mitigate by October 7 and conduct forensic triage; Canada's Cyber Centre issued advisory AV26-996 on October 5, and Australian authorities also warned customers. SecurityWeek said exploitation hit appliances patched days earlier and called this the sixth exploited NetScaler flaw added to KEV in 2026, while other reports described attacks on unpatched or unmitigated systems; researchers including Kevin Beaumont reported crash loops, commands hidden in usernames, webshell attempts, and a downloaded malware binary, so accounts disagree on remote code execution and patched-appliance impact. Separately, CVE-2026-88771, a CVSS 9.5 pre-authentication command-injection flaw patched on September 27 in 14.1-73.37 and 13.1-64.23, and CVE-2026-88772 remain under active exploitation, with LevelBlue reporting reverse shells, superuser sec_monitor, ns.conf theft, and a PHP web shell, and Mandiant citing likely victims across government, finance, technology, education, and legal services in North America and Europe.
- CVE-2026-88779 is a CVSS 8.7 memory-buffer overflow in customer-managed Citrix NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider, or with SAML Gateway or AAA.
- Fixed releases cited include 14.1-73.41 and 13.1-64.28, with matching FIPS builds; Canada's Cyber Centre said affected ADC builds are those before 13.1-37.282, 13.1-64.28, and 14.1-73.41, and Gateway builds before 13.1-64.28 and 14.1-73.41.
- CISA added CVE-2026-88779 to the KEV catalog on October 4, 2026, and ordered U.S. federal agencies to mitigate by October 7 and perform forensic triage; SecurityWeek called it the sixth exploited NetScaler flaw added to KEV in 2026.
- Citrix reported targeted denial-of-service attacks on unmitigated appliances, said data integrity was unaffected, published deny-list signatures and an indicator script, and credited watchTowr and Bishop Fox.
Coverage timelineoldest first · each row is one article
- · 8d agoCitrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update
GBHackers· 76
Patched Citrix NetScaler appliances crash and reboot when malformed SAML requests hit the nsaaad service.
Vulnerabilities in this storyAll →
- CVE-2025-65439.211%Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wildpublished · Citrix NetScaler ADC KEV