we_are_coded.by CODE · The world, decoded
БГ
Citrix

A third NetScaler hole lands in KEV within seven days, and if your NetScaler runs SAML, you upgrade again

CISA · event date: 4 October 2026Security

CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway that can take the service down. Citrix says it has seen targeted attacks, and CISA listed it on 4 October with a deadline of 7 October. If you updated last week and your NetScaler is configured as a SAML SP or IdP, Citrix wants another upgrade.

In short
  • CVE-2026-88779: memory overflow (CWE-119), denial of service, CVSS v4.0 8.7. Customer-managed deployments only.
  • The precondition per the bulletin: the appliance is configured as a SAML SP or SAML IdP. Sign in the config: add authentication samlAction or add authentication samlIdPProfile.
  • Fixed versions: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282. Those who upgraded per the 27 September bulletin, with the same precondition, upgrade again.
Checked on5 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

You updated NetScaler last week. Good. If SAML runs on it, you are not done.

The facts: on 4 October 2026 CISA added CVE-2026-88779 to the KEV catalog with a federal deadline of 7 October, a forensic triage requirement and ransomware use marked unknown. The flaw is in Citrix NetScaler ADC and NetScaler Gateway: a memory overflow (CWE-119) that under specific conditions leads to denial of service; CVSS v4.0 8.7. In a blog by the NetScaler Cyber Threat Intelligence team, Citrix says it has observed targeted attacks on unmitigated deployments, that if the condition is triggered repeatedly the service may remain unavailable, and that it has not identified an impact on data integrity. Only customer-managed deployments are affected: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS and NDcPP before 13.1-37.282. Per bulletin CTX697174, the precondition is that the appliance is configured as a SAML SP (the line add authentication samlAction in the configuration) or as a SAML IdP (the line add authentication samlIdPProfile); in the blog Citrix ties the issue to SAML authentication together with Gateway or AAA, and names the bulletin as the authoritative statement. Cloud services that Citrix itself manages are updated by the company. As a mitigation Citrix released signatures through the Global Deny List, but recommends upgrading. If you upgraded with the versions from the bulletin for CVE-2026-88771 through CVE-2026-88778 and the preconditions apply to you, Citrix asks for another upgrade, to the versions for this vulnerability.

What goes down here is the service. Citrix has found no impact on the integrity of the data. But NetScaler is the door people use to get into the company from outside, and while it keeps going down, that door stays shut.

First, see whether it concerns you. In the configuration you look for the two lines from the facts. No SAML, and Citrix's precondition is not met. With SAML, the version decides.

When NetScaler goes down, nobody gets into the company from outside.

The Global Deny List signatures are a bridge. They work through NetScaler Console and only in a narrow window: 14.1 from 73.37 to below 73.41, 13.1 from 64.23 to below 64.28. Citrix presents them as help, while you plan the upgrade.

Upgraded to 14.1-73.37 or 13.1-64.23 and the SAML precondition applies to you? The next version is 14.1-73.41 or 13.1-64.28. CISA's deadline runs out on Wednesday.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog, CVE-2026-88779, 04.10.2026→Citrix - Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779, CTX697174, 04.10.2026→Citrix - Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway, 04.10.2026
Original: https://wearecoded.com/en/articles/citrix-netscaler-cve-2026-88779-dos.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news