Less than a week after Cloud Software Group released fixes for eight NetScaler ADC and NetScaler Gateway vulnerabilities, including two actively exploited remote-code-execution zero-days, Citrix published a separate advisory for CVE-2026-88779.
CVE-2026-88779 affects SAML-enabled deployments
Citrix describes CVE-2026-88779 as a high-severity memory overflow vulnerability that can lead to denial of service. The vulnerability has a CVSS v4.0 base score of 8.7 and affects customer-managed NetScaler ADC and NetScaler Gateway deployments configured as either a SAML service provider or a SAML identity provider.
Citrix says it has observed targeted attacks against unmitigated NetScaler deployments. If the condition is triggered repeatedly, the service may remain unavailable. Citrix’s published analysis says the issue affects service availability and that it has not identified an impact on the integrity of customer data.
According to the Canadian Centre for Cyber Security, CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026. The Cyber Centre also said Citrix indicates that the vulnerability is exploited in the wild.
The configuration check is narrow but significant for remote-access environments. Citrix says administrators can determine whether the precondition applies by inspecting NetScaler configuration for either of these entries:
add authentication samlAction, indicating SAML SP configurationadd authentication samlIdPProfile, indicating SAML IdP configuration
The bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway. Citrix says Citrix-managed cloud services and Citrix-managed Adaptive Authentication are being upgraded by Cloud Software Group. Secure Private Access Hybrid deployments using NetScaler instances are also affected and need the relevant updates.
The fixed versions changed in less than a week
Citrix lists the following fixed releases for CVE-2026-88779 in its October 3 advisory:
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases
That creates the awkward patching overlap. The September 27 bulletin for CVE-2026-88771 through CVE-2026-88778 listed earlier fixed builds, including 14.1-73.37 and 13.1-64.23. Those builds addressed the previous disclosure, but they are not the fixed versions for the new SAML-related issue where CVE-2026-88779 applies.
The previous alert remains part of the response
The earlier NetScaler bulletin covered eight vulnerabilities. Two of them, CVE-2026-88771 and CVE-2026-88772, were the most urgent because Citrix and CISA said they were already being exploited.
CVE-2026-88771 is an improper input validation flaw that can allow unauthenticated remote command execution and applies to all NetScaler ADC and NetScaler Gateway deployments, including default configurations. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, which Citrix says is the default on VPN virtual servers.
CISA said both earlier flaws are critical zero-day vulnerabilities that can independently enable remote code execution, and that threat actors were actively exploiting them globally. CISA also urged organizations to check for signs of compromise before patching where possible, because updates may reduce forensic visibility.
Mandiant and Google Threat Intelligence Group said CVE-2026-88772 exploitation had been ongoing since at least early September and described post-exploitation tools including WHIPSHOT web shells and the SLAPSHOT Python tunneler in observed intrusions. That context is why several government advisories pair patching with compromise assessment instead of treating the update as the full response.
Reports of patched appliances crashing came first
SecurityWeek and BleepingComputer reported that administrators saw repeated reboots and crashes on NetScaler appliances that had already been updated to 14.1-73.37, the build issued for the previous disclosure. Some public reports involved SAML authentication and repeated nsaaad crashes before Citrix published the CVE-2026-88779 advisory.
Those reports are not the same as official vendor confirmation of remote code execution through CVE-2026-88779. Citrix’s published assessment limits the confirmed impact of this new vulnerability to service availability. SecurityWeek later reported that watchTowr reproduced CVE-2026-88779 and determined it could only be used to crash systems, while suspecting the crash behavior may have been used to make exploitation of CVE-2026-88771 faster.
Compromise checks are still part of the job
Citrix’s immediate direction is to upgrade affected systems to the fixed builds. The company also says Global Deny List signatures can reduce exposure while customers validate applicability and plan the upgrade, but Citrix still recommends installing software versions containing the fix as soon as possible.
The Canadian Cyber Centre warned on October 3 that patching alone may not fully remediate systems previously compromised through the earlier vulnerabilities because persistence mechanisms may remain.
For exposed deployments, the current advisories point to a layered response:
- Identify customer-managed NetScaler ADC and NetScaler Gateway deployments using SAML SP or SAML IdP configurations.
- Verify whether affected systems are on the CVE-2026-88779 fixed builds for the relevant 14.1, 13.1, FIPS, or NDcPP track.
- Use NetScaler Console and official indicator-of-compromise tooling where available, especially for internet-facing appliances.
- Preserve forensic evidence before disruptive changes where compromise is suspected and operational conditions allow it.
- Treat confirmed or suspected compromise as an incident, including isolation, high-availability pair review, credential rotation after patching, and downstream Citrix infrastructure review.
The relevant exposure changed from all deployments for one CVE, to DTLS-enabled systems for another, to SAML SP or IdP deployments for the latest advisory. Treat each advisory as its own exposure check, not just a yes-or-no answer to whether the September 27 emergency build was installed.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







