CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway that can take the service down. Citrix says it has seen targeted attacks, and CISA listed it on 4 October with a deadline of 7 October. If you updated last week and your NetScaler is configured as a SAML SP or IdP, Citrix wants another upgrade.
- CVE-2026-88779: memory overflow (CWE-119), denial of service, CVSS v4.0 8.7. Customer-managed deployments only.
- The precondition per the bulletin: the appliance is configured as a SAML SP or SAML IdP. Sign in the config: add authentication samlAction or add authentication samlIdPProfile.
- Fixed versions: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282. Those who upgraded per the 27 September bulletin, with the same precondition, upgrade again.
You updated NetScaler last week. Good. If SAML runs on it, you are not done.
What goes down here is the service. Citrix has found no impact on the integrity of the data. But NetScaler is the door people use to get into the company from outside, and while it keeps going down, that door stays shut.
First, see whether it concerns you. In the configuration you look for the two lines from the facts. No SAML, and Citrix's precondition is not met. With SAML, the version decides.
The Global Deny List signatures are a bridge. They work through NetScaler Console and only in a narrow window: 14.1 from 73.37 to below 73.41, 13.1 from 64.23 to below 64.28. Citrix presents them as help, while you plan the upgrade.
Upgraded to 14.1-73.37 or 13.1-64.23 and the SAML precondition applies to you? The next version is 14.1-73.41 or 13.1-64.28. CISA's deadline runs out on Wednesday.