CVE-2026-88779

LOWCVSS 8.7 · HIGHCISA KEV

Signal is active with 13 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 13 mentions across 1 observed day

What's happening

  • 13 total mentions across 1 day

Deep dive

Activity timeline13 mentions / 1d
0371013Mentions · 2026-10-04: 1310-04
Referenced assets6 URLs
Full discourse13 posts
  • Citrix@citrix

    We have a new security update: Understanding and addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway: https://bit.ly/3U8A9uO

    210333124.4K
    197.2K followersView on X
  • Thomas Poppelgaard@_POPPELGAARD

    Patched @NetScaler for CTX697096 and use SAML? Patch again. CVE-2026-88779 is a separate bulletin, CTX697174 (CVSS 8.7), not part of CTX697096. It's the SAML attack crashing patched NetScalers since 2 Oct. @citrix sees targeted attacks. Affected: "add authentication samlAction" or "samlIdPProfile" in ns.conf Fixed: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 Interim: Global Deny List (NetScaler Console) or Citrix Support's responder policy, -type AAA_REQUEST on every Gateway/AAA vserver Free checker v1.12 covers both bulletins: • CVE-2026-88779 on every run • SAML policy coverage per vserver • "may have run" window ends at the fix • 98 IPs, 16 domains, 34 hashes Thanks to @GothamTG , @BeazleySecurity , @Deyda84 , @citrixguyblog , @rjfaulknerjr @FerroqueSystems, @bishopfox , @watchtowrcyber and the community 🙏 #NetScaler #Citrix #CitrixNetScaler #NetScalerGateway #CVE202688779 #CVE202688771 #CTX697174 #CTX697096 #CyberSecurity #InfoSec #IncidentResponse #ThreatHunting

    01043298
    4.3K followersView on X
  • ThreatWire@ThreatWire_

    🚨 EXPLOITED IN THE WILD: Citrix NetScaler CVE-2026-88779 is being targeted in attacks against SAML-configured deployments. The high-severity flaw (CVSS 8.7) is a memory-overflow vulnerability that can cause denial of service. ⚠️ Affected when NetScaler ADC/Gateway is configured as a SAML SP or SAML IdP. 🔴 Upgrade to: • 14.1-73.41+ • 13.1-64.28+ • 14.1-73.41 FIPS+ • 13.1-37.282+ for FIPS/NDcPP This is a new NetScaler issue separate from the CVE-2026-88771/88772 zero-days disclosed last week. Source: Citrix Security Bulletin #CVE #CyberSecurity #InfoSec #Citrix #NetScaler #SAML

    01060268
    1.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now. #Citrix #NetScaler #CVE202688779 #SAML #ActivelyExploited #DoS #Vulnerability https://securityonline.info/citrix-netscaler-cve-2026-88779-exploited/

    00031436
    13.0K followersView on X
  • Previdian@PrevidianCyber

    CVE-2026-88779 has been assigned to the Netscaler vulnerability being exploited in the wild.

    01021292
    137 followersView on X
  • Radical Edward (Citrix Janitor)@RadicalEdward13

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174

    01001150
    36 followersView on X
  • VulDB 🛡@vuldb

    A severe vulnerability was disclosed for Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88779) vuldb.​com/vuln/413388

    00010233
    2.3K followersView on X
  • Chris Nyhuis@vigilance_one

    Patched your NetScaler last weekend? You may need to patch it again. Citrix just formally disclosed CVE-2026-88779 and released updated builds. Important: this does NOT affect every NetScaler. You’re affected if you’re running a NetScaler Gateway or AAA virtual server AND using SAML authentication. If you don’t have that configuration, this vulnerability doesn’t apply to you. If you do, even if you patched last weekend, you need to look again. The previous updates for CVE-2026-88771/88772 do not fix this vulnerability. Fixed builds: • 14.1 → 14.1-73.41+ • 13.1 → 13.1-64.28+ Citrix says it has observed targeted attacks against unmitigated deployments. No panic. Check your configuration, determine your exposure, patch if applicable, and keep hunting. Remember patching closes the vulnerability. It doesn’t tell you what happened before you patched

    00010176
    115 followersView on X
  • 2logics@2logics

    Cloud Software Group published a NetScaler security bulletin for CVE-2026-88779 on October 3, 2026 Pacific time, according to the bulletin changelog, covering customer-managed Citrix NetScaler ADC and NetScaler Gateway. The issue is a memory-overflow vulnerability that can lead to denial of service. Citrix scored it CVSS v4.0 8.7. It applies when the appliance is configured as a SAML service provider or a SAML identity provider. Citrix said affected supported builds are 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, 14.1-FIPS before 14.1-73.41 FIPS, and 13.1-FIPS and 13.1-NDcPP before 13.1-37.282. The fixed lines are those same version numbers and later releases. Secure Private Access hybrid deployments that use customer-managed NetScaler instances are included. Citrix said this bulletin does not apply to Citrix-managed cloud services or Citrix-managed Adaptive Authentication, which the company updates itself. The bulletin thanks Bishop Fox and watchTowr. Severity is listed as High. This is a new dated bulletin for CVE-2026-88779, not a reprint of the late-September KEV note on the earlier NetScaler zero-days. Why it matters: a vendor bulletin with a CVE, a CVSS score, a narrow SAML precondition, and named fixed builds, limited to customer-managed appliances. Sources: Citrix / Cloud Software Group, CTX697174, 3 Oct 2026. #Citrix #NetScaler #CVE #Cybersecurity #SAML #InfoSec #TechNews @citrix

    0000031
    30 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    CitrixがNetScalerの新たな脆弱性CVE-2026-88779の修正版を公開 — SAML認証環境で停止のおそれ、標的型攻撃も確認 https://cyber.nexsight.co/articles/2026/10/04/netscaler-cve-2026-88779-saml-dos-fix-2026-10-04/

    0000038
    76 followersView on X
  • CVE@CVEnew

    CVE-2026-88779 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; G… https://www.cve.org/CVERecord?id=CVE-2026-88779

    00000370
    58.1K followersView on X
  • PeritumAI@peritumAI

    @citrix SAML SP or IdP only — that's the precondition that decides whether CVE-2026-88779 is your problem tonight. Floor is 14.1-73.41 / 13.1-64.28. After last week's RCE week, another NetScaler bulletin lands and nobody's surprised.

    00000176
    334 followersView on X
  • tadmaddad@tadmaddad

    こちらの件、CVE-2026-88779 として出たようです。 「CVE-2026-88779は、Citrix NetScaler ADCおよびCitrix NetScaler Gatewayにおけるメモリオーバーフローの脆弱性であり、特定の展開条件下でサービス拒否を引き起こす可能性があります。」 https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/

    00000122
    613 followersView on X

Explore more