
We have a new security update: Understanding and addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway: https://bit.ly/3U8A9uO
Signal is active with 13 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
NONE
Momentum
NONE

We have a new security update: Understanding and addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway: https://bit.ly/3U8A9uO

Patched @NetScaler for CTX697096 and use SAML? Patch again. CVE-2026-88779 is a separate bulletin, CTX697174 (CVSS 8.7), not part of CTX697096. It's the SAML attack crashing patched NetScalers since 2 Oct. @citrix sees targeted attacks. Affected: "add authentication samlAction" or "samlIdPProfile" in ns.conf Fixed: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 Interim: Global Deny List (NetScaler Console) or Citrix Support's responder policy, -type AAA_REQUEST on every Gateway/AAA vserver Free checker v1.12 covers both bulletins: • CVE-2026-88779 on every run • SAML policy coverage per vserver • "may have run" window ends at the fix • 98 IPs, 16 domains, 34 hashes Thanks to @GothamTG , @BeazleySecurity , @Deyda84 , @citrixguyblog , @rjfaulknerjr @FerroqueSystems, @bishopfox , @watchtowrcyber and the community 🙏 #NetScaler #Citrix #CitrixNetScaler #NetScalerGateway #CVE202688779 #CVE202688771 #CTX697174 #CTX697096 #CyberSecurity #InfoSec #IncidentResponse #ThreatHunting

🚨 EXPLOITED IN THE WILD: Citrix NetScaler CVE-2026-88779 is being targeted in attacks against SAML-configured deployments. The high-severity flaw (CVSS 8.7) is a memory-overflow vulnerability that can cause denial of service. ⚠️ Affected when NetScaler ADC/Gateway is configured as a SAML SP or SAML IdP. 🔴 Upgrade to: • 14.1-73.41+ • 13.1-64.28+ • 14.1-73.41 FIPS+ • 13.1-37.282+ for FIPS/NDcPP This is a new NetScaler issue separate from the CVE-2026-88771/88772 zero-days disclosed last week. Source: Citrix Security Bulletin #CVE #CyberSecurity #InfoSec #Citrix #NetScaler #SAML

Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now. #Citrix #NetScaler #CVE202688779 #SAML #ActivelyExploited #DoS #Vulnerability https://securityonline.info/citrix-netscaler-cve-2026-88779-exploited/

CVE-2026-88779 has been assigned to the Netscaler vulnerability being exploited in the wild.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174

A severe vulnerability was disclosed for Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88779) vuldb.com/vuln/413388

Patched your NetScaler last weekend? You may need to patch it again. Citrix just formally disclosed CVE-2026-88779 and released updated builds. Important: this does NOT affect every NetScaler. You’re affected if you’re running a NetScaler Gateway or AAA virtual server AND using SAML authentication. If you don’t have that configuration, this vulnerability doesn’t apply to you. If you do, even if you patched last weekend, you need to look again. The previous updates for CVE-2026-88771/88772 do not fix this vulnerability. Fixed builds: • 14.1 → 14.1-73.41+ • 13.1 → 13.1-64.28+ Citrix says it has observed targeted attacks against unmitigated deployments. No panic. Check your configuration, determine your exposure, patch if applicable, and keep hunting. Remember patching closes the vulnerability. It doesn’t tell you what happened before you patched

Cloud Software Group published a NetScaler security bulletin for CVE-2026-88779 on October 3, 2026 Pacific time, according to the bulletin changelog, covering customer-managed Citrix NetScaler ADC and NetScaler Gateway. The issue is a memory-overflow vulnerability that can lead to denial of service. Citrix scored it CVSS v4.0 8.7. It applies when the appliance is configured as a SAML service provider or a SAML identity provider. Citrix said affected supported builds are 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, 14.1-FIPS before 14.1-73.41 FIPS, and 13.1-FIPS and 13.1-NDcPP before 13.1-37.282. The fixed lines are those same version numbers and later releases. Secure Private Access hybrid deployments that use customer-managed NetScaler instances are included. Citrix said this bulletin does not apply to Citrix-managed cloud services or Citrix-managed Adaptive Authentication, which the company updates itself. The bulletin thanks Bishop Fox and watchTowr. Severity is listed as High. This is a new dated bulletin for CVE-2026-88779, not a reprint of the late-September KEV note on the earlier NetScaler zero-days. Why it matters: a vendor bulletin with a CVE, a CVSS score, a narrow SAML precondition, and named fixed builds, limited to customer-managed appliances. Sources: Citrix / Cloud Software Group, CTX697174, 3 Oct 2026. #Citrix #NetScaler #CVE #Cybersecurity #SAML #InfoSec #TechNews @citrix

CitrixがNetScalerの新たな脆弱性CVE-2026-88779の修正版を公開 — SAML認証環境で停止のおそれ、標的型攻撃も確認 https://cyber.nexsight.co/articles/2026/10/04/netscaler-cve-2026-88779-saml-dos-fix-2026-10-04/

CVE-2026-88779 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; G… https://www.cve.org/CVERecord?id=CVE-2026-88779

@citrix SAML SP or IdP only — that's the precondition that decides whether CVE-2026-88779 is your problem tonight. Floor is 14.1-73.41 / 13.1-64.28. After last week's RCE week, another NetScaler bulletin lands and nobody's surprised.

こちらの件、CVE-2026-88779 として出たようです。 「CVE-2026-88779は、Citrix NetScaler ADCおよびCitrix NetScaler Gatewayにおけるメモリオーバーフローの脆弱性であり、特定の展開条件下でサービス拒否を引き起こす可能性があります。」 https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/