Citrix has patched a new NetScaler zero-day, CVE-2026-88779, that attackers were already exploiting before a fix shipped. The flaw is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that crashes appliances configured as a SAML service provider or identity provider, and CISA added it to its Known Exploited Vulnerabilities catalog on October 4, 2026, giving federal agencies until October 7 to patch. It’s Citrix’s second emergency NetScaler bulletin in under two weeks.
What CVE-2026-88779 Actually Does
According to Citrix’s own security bulletin (CTX697174), the bug carries a CVSS 4.0 score of 8.7 and is described plainly as a memory overflow vulnerability leading to denial of service. It only affects appliances where SAML is actually configured, either as a service provider or an identity provider, not the default out-of-the-box setup. That’s narrower than the pair of NetScaler flaws Citrix patched on September 27, where one of the two bugs hit every deployment regardless of configuration.
Narrower doesn’t mean low priority here. The Hacker News reports the flaw was found and exploited in targeted attacks before Citrix had a patch ready, with researchers at Bishop Fox and watchTowr credited in the disclosure. BleepingComputer’s coverage notes that while Citrix classifies it strictly as a crash-inducing DoS bug, some researchers monitoring exploitation activity suspect the memory corruption could potentially be pushed further than a simple denial of service.
Affected and Fixed Versions
- NetScaler ADC / Gateway 14.1 before 14.1-73.41, fixed in 14.1-73.41 and later
- NetScaler ADC / Gateway 13.1 before 13.1-64.28, fixed in 13.1-64.28 and later
- NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS, fixed in 14.1-73.41 FIPS and later
- NetScaler ADC/Gateway 13.1-FIPS and 13.1-NDcPP before 13.1-37.282, fixed in 13.1-37.282 and later
Who Needs to Act
If you run NetScaler ADC or Gateway as a SAML identity provider or service provider, for SSO into internal apps or as a VPN gateway tied into SAML-based auth, patch now rather than waiting for a maintenance window. CISA’s short federal deadline is a signal of how seriously the agency is treating active exploitation, not just a government-only concern. Worth checking logs for unexpected appliance restarts or crashes around the SAML processing path since the patch shipped, since that’s consistent with exploitation attempts against this bug.
This is the second NetScaler zero-day Citrix has had to rush out a fix for since late September, following the CVE-2026-88771 and CVE-2026-88772 pair patched on September 27. Two emergency bulletins on the same product line inside two weeks is a pattern worth noticing if NetScaler sits anywhere in your infrastructure: whoever owns patching for it should be on a short notification cycle for Citrix advisories right now, not checking in once a quarter.



