BREAKING: NetScaler SAML memory overflow hits CISA KEV
How to fix CVE-2026-88779: upgrade NetScaler ADC/Gateway to 14.1-73.41 or 13.1-64.28 (SAML SP/IdP builds)
Contents
CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog today (2026-10-04). The bug is a memory-buffer overflow in customer-managed Citrix NetScaler ADC and NetScaler Gateway that can take the appliance down with a denial of service. CISA's short description matches Citrix: improper restriction of operations within the bounds of a memory buffer. KEV due date is 2026-10-07. Required action follows BOD 26-04 (risk-based patching plus forensic triage where applicable). Catalog version is 2026.10.04.
Citrix published security bulletin CTX697174 (initial publication 2026-10-03 PST). Vendor CVSS v4.0 base is 8.7 High with availability impact High and confidentiality/integrity None (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). CWE-119. Citrix thanks Bishop Fox and watchTowr. This page is the operator write-up from CISA KEV and the Citrix bulletin. The HOL Guard evidence pack for CVE-2026-88779 is the linked source record.
What breaks
On a NetScaler configured as a SAML SP or SAML IdP, an attacker who can reach the SAML authentication path can trigger a memory overflow that takes the appliance into denial of service. Citrix clocks the precondition explicitly: the box must have add authentication samlAction (SP) or add authentication samlIdPProfile (IdP) in the running config. No login is required on the CVSS vector (PR:N, UI:N). Impact is availability of the gateway/ADC, not remote code execution.
Affected customer-managed trains (Citrix bulletin):
- NetScaler ADC and Gateway 14.1 before 14.1-73.41
- NetScaler ADC and Gateway 13.1 before 13.1-64.28
- NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS
- NetScaler ADC 13.1-FIPS / 13.1-NDcPP before 13.1-37.282
Secure Private Access Hybrid deployments that use customer-managed NetScaler instances are also in scope for those instances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by Cloud Software Group; this bulletin is for customer-managed appliances.
This is a different CVE from the September NetScaler RCE cluster (CVE-2026-88771 through CVE-2026-88778). Those were a separate bulletin and KEV wave. Do not treat an already-patched 88771 box as automatically safe for 88779: confirm you are on the builds listed above.
Who is not in scope
- NetScaler appliances with no SAML SP and no SAML IdP config. If the running config has neither
samlActionnorsamlIdPProfile, Citrix's stated precondition is not met. - Citrix-managed cloud / Adaptive Authentication that Cloud Software Group patches on your behalf (confirm with your Citrix cloud status if you are unsure).
- Other Citrix products (Workspace app, StoreFront, XenDesktop, and so on). This ID is NetScaler ADC/Gateway only.
- The September unauthenticated RCE path (CVE-2026-88771 / siblings). Different bulletin, different fix trains (14.1-73.37 / 13.1-64.23 class). Patch both if you are behind on either wave.
One operator check
On each customer-managed NetScaler, confirm build and whether SAML auth objects exist:
# CLI: show the running build
show version
# Expect at least:
# 14.1-73.41+ or 13.1-64.28+
# (FIPS/NDcPP: 14.1-73.41 FIPS+ or 13.1-37.282+)
# Precondition: SAML SP or SAML IdP present?
show running-config | grep -i samlAction
show running-config | grep -i samlIdPProfile
If either samlAction or samlIdPProfile lines appear and show version is below the fixed builds, you are in the KEV blast radius. Federal and BOD 26-04 environments also owe forensic triage before they declare the host clean; KEV due date is 2026-10-07.
How to fix
Citrix's required action: install the fixed builds as soon as possible.
# Target builds (pick the train you run)
# NetScaler ADC / Gateway 14.1 -> 14.1-73.41 or later
# NetScaler ADC / Gateway 13.1 -> 13.1-64.28 or later of 13.1
# NetScaler ADC 14.1-FIPS -> 14.1-73.41 FIPS or later
# NetScaler ADC 13.1-FIPS/NDcPP -> 13.1-37.282 or later
# After upgrade, re-check
show version
There is no Citrix-published temporary workaround in CTX697174 beyond upgrading. If you cannot patch in the KEV window, remove public exposure to the SAML authentication endpoints where operations allow, preserve forensic evidence before you wipe the box, and follow CISA BOD 26-04 triage notes linked from the KEV row.
SPA Hybrid operators: upgrade every customer-managed NetScaler instance tied to the hybrid path, not only the "primary" ADC.
What this is not
This is not unauthenticated remote code execution. Citrix and CISA describe denial of service from a memory-buffer defect on SAML-configured appliances. It is also not automatic coverage from the September 88771 RCE patch alone: confirm the 88779 builds. And it is not "wait for NVD to finish enrichment before acting": CISA already listed the CVE with due date 2026-10-07.
References
- CISA KEV CVE-2026-88779 (dateAdded 2026-10-04, dueDate 2026-10-07, catalogVersion 2026.10.04)
- Citrix CTX697174 (NetScaler ADC/Gateway Security Bulletin for CVE-2026-88779)
- Citrix community context post for CVE-2026-88779
- NVD CVE-2026-88779
- CVE-2026-88779
- HOL prior write-up: CVE-2026-88771 NetScaler unauthenticated RCE (separate September cluster)
Continue reading
All posts
BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

Zammad session fixation to root hits CISA KEV
How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)

FortiMail unauthenticated path traversal hits CISA KEV
How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to upcoming 8.0.2 / 7.6.7 / 7.4.9
