Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | CVE-2026-88779: Citrix NetScaler Zero-Day
Oct 06, 2026
4 Mins Read
Moon
Summarize with:

CVE-2026-88779: Citrix NetScaler Zero-Day

Citrix has patched CVE-2026-88779, a high-severity NetScaler vulnerability that was exploited as a zero-day before fixes became available. The memory overflow affects customer-managed NetScaler ADC and NetScaler Gateway appliances using SAML authentication and can cause Denial of Service (DoS) conditions.

CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026, with an October 7 remediation deadline for covered federal agencies.

What Is CVE-2026-88779?

CVE-2026-88779 is a memory overflow vulnerability classified as CWE-119. It affects NetScaler appliances configured as either a SAML service provider (SP) or SAML identity provider (IdP). Citrix assigned the flaw a CVSS v4.0 score of 8.7 (High). It is remotely reachable, requires no privileges or user interaction, and carries high availability impact. Citrix does not assign confidentiality or integrity impact to the vulnerability.

Details of CVE-2026-88779 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-88779 (SOCRadar Vulnerability Intelligence)

The confirmed impact is denial of service. Citrix has not established that CVE-2026-88779 reliably enables remote code execution, authentication bypass, or data theft.

Which NetScaler Versions Are Affected?

Citrix identifies the following vulnerable branches:

Product Affected Fixed Version
NetScaler ADC / Gateway 14.1 Before 14.1-73.41 14.1-73.41 or later
NetScaler ADC / Gateway 13.1 Before 13.1-64.28 13.1-64.28 or later
NetScaler ADC 14.1-FIPS Before 14.1-73.41 FIPS 14.1-73.41 FIPS or later
NetScaler ADC 13.1-FIPS / NDcPP Before 13.1-37.282 13.1-37.282 or later

The vulnerability also requires one of these SAML configurations:

  • add authentication samlAction
  • add authentication samlIdPProfile

Citrix provides the affected builds, configuration checks, and remediation instructions in its CVE-2026-88779 NetScaler security bulletin.

Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected. Citrix-managed cloud services are updated by the provider.

How Could CVE-2026-88779 Be Exploited?

An attacker needs network access to a vulnerable NetScaler service configured for SAML. Specially crafted traffic can trigger unsafe memory handling in the SAML processing path, causing authentication services or the appliance to crash.

Repeated triggering may keep the affected service unavailable, potentially interrupting VPN, Gateway, AAA, or application access.

The exact triggering request and vulnerable memory operation have not been publicly disclosed. Citrix says its analysis indicates an availability impact and has not identified an impact on customer data integrity.

Is Public PoC Code Available?

As of October 6, no credible fully weaponized public exploit has been identified.

watchTowr reproduced the vulnerability while working with Citrix, but private reproduction by a security research team is different from publishing working exploit code.

The lack of a public PoC does not reduce urgency because attackers were already exploiting the vulnerability before patches were available.

Was CVE-2026-88779 Exploited?

Yes. CVE-2026-88779 was exploited before Citrix released patches, making it a zero-day vulnerability during the observed attacks.

Administrators began reporting crashes and repeated reboots on fully patched NetScaler appliances before Citrix published the CVE and fixed builds on October 3. Citrix subsequently confirmed targeted attacks against unmitigated deployments.

CISA added CVE-2026-88779 to KEV on October 4, confirming exploitation in the wild and setting an October 7, 2026 remediation deadline for covered federal agencies.

Reports of shell commands, downloaded malware, or other suspicious activity around affected appliances should be treated cautiously. Current research supports CVE-2026-88779 as a DoS vulnerability, but does not establish that the flaw itself provides reliable command execution.

Track CVE-2026-88779 with SOCRadar

SOCRadar’s Cyber Threat Intelligence capabilities can help teams monitor CVE-2026-88779 for exploitation developments, public exploit availability, and remediation updates. Combined with Attack Surface Management, organizations can identify internet-facing NetScaler assets and prioritize SAML-enabled systems that require immediate version and configuration validation.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

What Should Defenders Do?

Upgrade Affected Appliances

Citrix strongly urges customers to install fixed builds as soon as possible. Appliances already updated for the earlier CVE-2026-88771 through CVE-2026-88778 issues may still require this newer update.

NetScaler Console can identify affected systems under CVE Detection → Impacted Instances and launch the upgrade process. NetScaler documents the workflow in its CVE-2026-88779 remediation guidance.

Verify SAML Exposure

Search configurations for:

  • add authentication samlAction
  • add authentication samlIdPProfile

Systems without these configurations fall outside Citrix’s stated vulnerability precondition.

Hunt for Suspicious Activity

Review affected appliances for:

  • Repeated authentication service crashes.
  • Unexpected restarts or reboot loops.
  • SAML authentication failures.
  • Unexplained Gateway or AAA instability.
  • Suspicious authentication inputs preceding crashes.
  • Unexpected outbound network activity.

Preserve relevant logs, support bundles, configuration data, and external telemetry if compromise is suspected.

Given that CVE-2026-88779 was exploited as a zero-day, organizations should prioritize internet-facing, SAML-enabled NetScaler appliances, upgrade to a fixed build, and investigate systems that experienced unexplained instability before the patches became available.