Cyber One Solutions logo.
Get Support

Security Advisory

CVE-2026-88779: A New Citrix NetScaler Flaw Joins CISA’s Known Exploited Vulnerabilities Catalog

October 6, 2026 · Cyber One Solutions Security Team

Citrix disclosed a separate NetScaler ADC and Gateway vulnerability on October 3, 2026, a memory overflow that can crash the appliance’s SAML authentication service. CISA added it to its Known Exploited Vulnerabilities catalog the next day, October 4, listing an October 7 due date and directing federal agencies to remediate based on each affected asset’s internet exposure under Binding Operational Directive 26-04. It is a different flaw from the NetScaler zero-days Citrix disclosed on September 27, and only applies to a customer-managed appliance on a vulnerable build with SAML authentication configured; Citrix patches its own hosted cloud services.

Cloud Software Group, Citrix's parent company, published security bulletin CTX697174 on October 3, 2026, disclosing CVE-2026-88779 in NetScaler ADC and NetScaler Gateway. Citrix's bulletin assigns the flaw a CVSS v4.0 base score of 8.7 (vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N) and describes it as a memory overflow that can be triggered when the appliance is configured as a SAML Service Provider or a SAML Identity Provider, leading to denial of service. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog the next day, October 4, 2026, listing an October 7, 2026 due date and flagging the entry for forensic triage, according to CISA's KEV catalog entry. That entry's required action directs federal civilian agencies to remediate in accordance with Binding Operational Directive 26-04, which bases the applicable timeline on each affected asset's internet exposure, so the specific deadline for a given federal appliance depends on whether it is publicly exposed. CISA adds a vulnerability to that catalog only when it has reliable evidence the vulnerability is being exploited, so the listing itself is confirmation this flaw is already being used in attacks, even though Citrix's own bulletin text, unlike the one it published for the NetScaler flaws disclosed on September 27, does not itself state that Citrix has observed exploitation.

A Separate Flaw From the September 27 Disclosure

CVE-2026-88779 is not part of the eight-vulnerability bulletin, CTX697096, that Citrix published on September 27, 2026, which included the two actively exploited zero-days we covered at the time. This is a different bulletin and a different CVE from a different numeric block, disclosed six days later, reachable only under a different configuration. The September 27 flaws were reachable in NetScaler's default configuration or on appliances with DTLS enabled for VPN virtual servers; CVE-2026-88779 only affects an appliance configured to use SAML authentication, either as a Service Provider or an Identity Provider. An organization that already patched for the September 27 disclosure and does not use NetScaler for SAML authentication is not described by Citrix as affected by this separate flaw. One that does use NetScaler for SAML, whether for single sign-on into internal applications or as the identity source behind the Gateway login itself, needs this separate update regardless of whether it already applied the September patch.

Affected and Fixed Versions

Citrix's bulletin lists NetScaler ADC and Gateway 14.1 before build 14.1-73.41, and 13.1 before build 13.1-64.28, as affected, along with the corresponding FIPS build (before 14.1-73.41 FIPS) and FIPS/NDcPP build (before 13.1-37.282). The fixed releases are 14.1-73.41 and later, and 13.1-64.28 and later, with matching FIPS and NDcPP builds. These are newer build numbers than the fixes for the September 27 disclosure (14.1-73.37 and 13.1-64.23), so an appliance patched only for that earlier bulletin is still below the fixed build for this one and needs the newer update applied separately. As with the September disclosure, NetScaler 12.1 and 13.0 are past end of life and have no vendor fix for this issue either. Citrix's bulletin also states this applies only to customer-managed NetScaler ADC and NetScaler Gateway; Cloud Software Group patches its own Citrix-managed cloud services and Citrix-managed Adaptive Authentication directly, so those do not need customer action.

What the Flaw Actually Does

Citrix describes the impact as denial of service: an attacker who can reach the SAML authentication endpoint can send traffic that overflows memory and crashes or hangs the service, cutting off legitimate users rather than giving the attacker code execution or access to data. Security researchers Bishop Fox and watchTowr worked with Citrix on the issue before publication, and watchTowr, which published its own FAQ on the CVE, says its Rapid Reaction service identified which of its own clients were exposed and its Active Defense service pushed targeted network-level mitigations to them, without describing having independently reproduced the flaw itself. Citrix's own bulletin and CVSS vector are what establish the impact as denial of service rather than remote code execution. That distinction matters for how you prioritize this relative to the September 27 flaws, which Citrix confirmed were already being used for remote code execution before a patch existed. CVE-2026-88779 can still take a production authentication service offline, which for many organizations means employees or customers cannot sign in at all until the appliance is restarted and patched, but it is a narrower category of impact than a remote-code-execution flaw.

What to Do Now

Confirm whether any NetScaler ADC or Gateway appliance your organization or your IT provider operates is configured as a SAML Service Provider or SAML Identity Provider. If none are, this specific flaw does not apply, though confirming your build number against the September 27 fixes is still worthwhile on its own. Before making any changes to an appliance that has been internet-facing with SAML enabled, preserve its logs, support bundle, and any snapshot, and run the NetScaler Console indicator-of-compromise script Citrix and watchTowr both point to; CVE-2026-88779 itself is a denial-of-service flaw, not one Citrix describes as leading to compromise, but an appliance still below the September 27 fixed builds could have been exposed to that separate, concurrent campaign, and patching first can overwrite the evidence. Then check its build number against the fixed releases above. Before you apply the update, confirm your SAML identity provider issues signed assertions: the fixed build enforces signed SAML assertions and drops support for the samlRejectUnsignedAssertion OFF setting, so a deployment currently relying on that setting can lose SAML authentication entirely the moment it is upgraded unless the identity provider side is already issuing signed assertions. Test authentication immediately after upgrading rather than assuming it carried over. Apply the update on an emergency basis once that compatibility is confirmed, regardless of how recently you patched for the earlier bulletin. If you cannot apply the fixed build immediately, Citrix's companion guidance on this bulletin describes an interim Global Deny List mitigation, available through NetScaler Console when Virtual Patching is enabled, for appliances already on build 14.1-73.37 through 73.40 or 13.1-64.23 through 64.27; treat that as a stopgap while you schedule the upgrade, not a substitute for it. CISA's KEV catalog entry lists an October 7, 2026 due date for this CVE, three days after its October 4 addition, and flags it for forensic triage. The same entry directs federal agencies to evaluate each asset's internet exposure and follow Binding Operational Directive 26-04's patching timelines, so the deadline that applies to a particular federal appliance depends on whether it is publicly exposed; that still signals treating this as an emergency patch rather than a routine one.

What This Means for Your Risk-Management Obligations

For businesses subject to the FTC Safeguards Rule or the HIPAA Security Rule, the same obligations we have referenced in our recent coverage of Citrix and Cisco advisories apply here, with one addition: both frameworks also address system availability, not only confidentiality. The FTC Safeguards Rule's continuous-monitoring-or-periodic-testing requirement under 16 CFR 314.4(d)(2) applies to nonbanking financial institutions, though 16 CFR 314.6 exempts institutions maintaining customer information on fewer than 5,000 consumers from that subsection entirely, not merely from its periodic-testing option; those institutions' other Safeguards Rule obligations still apply. HHS Office for Civil Rights guidance treats maintaining the availability of systems that process protected health information, not only their confidentiality and integrity, as part of the HIPAA Security Rule's risk-analysis obligation at 45 CFR 164.308(a)(1)(ii)(A) and its related risk-management obligation at (B), the assessment and the implementation steps respectively. An authentication gateway that goes down under a known, patchable denial-of-service flaw falls squarely within those obligations.

If your organization runs NetScaler ADC or NetScaler Gateway with SAML authentication, confirm your build number today. Cyber One Solutions can confirm your NetScaler configuration, build numbers, and patch status as part of our IT and security assessments. Our managed cybersecurity service's vulnerability management program tracks advisories like this one against your actual environment and follows through to a validated fix, not just a patch notification.

Sources