Organisations that rushed to patch Citrix NetScaler last week have to do it again. On 3 October 2026, Cloud Software Group published bulletin CTX697174 for CVE-2026-88779. The flaw is a memory overflow in NetScaler ADC and NetScaler Gateway that an unauthenticated attacker can use to take the appliance offline. It affects appliances configured for SAML, either as a Service Provider or as an Identity Provider. The fixed builds, 14.1-73.41 and 13.1-64.28, supersede the emergency builds that Citrix shipped on 27 September for the actively exploited CVE-2026-88771 and CVE-2026-88772 (see our earlier coverage). Those 27 September builds (14.1-73.37 and 13.1-64.23) are vulnerable to CVE-2026-88779.

CVE-2026-88779: SAML-Path Memory Overflow

Citrix's bulletin titles the flaw "Memory overflow vulnerability leading to Denial of Service". It is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer) and scored 8.7 under CVSS v4.0. The vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N. That means it is reachable over the network with no authentication, no user interaction and no special attack requirements, and the only impact is on availability.

In its companion Tech Zone post, Citrix's NetScaler Cyber Threat Intelligence team says: "Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data." The team also warns that "if the condition is triggered repeatedly, the service may remain unavailable." For a NetScaler Gateway that is the only remote-access path for a workforce, or a SAML IdP that every federated application depends on, losing availability is a serious incident in itself.

Citrix has not published which SAML message, field or parsing step overflows. The bulletin's only precondition is the SAML role of the appliance:

  • SAML Service Provider: the configuration contains add authentication samlAction
  • SAML Identity Provider: the configuration contains add authentication samlIdPProfile

The blog adds that the issue "is associated with NetScaler deployments that use SAML authentication in conjunction with Gateway or AAA functionality".

Exploitation Status: What Citrix Says

The CTX697174 bulletin itself contains no statement about exploitation. The Tech Zone blog, which the bulletin's changelog links as "further context", says: "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service." Citrix has not published indicators of compromise, source addresses or attack volumes for CVE-2026-88779. As of CISA's 2 October catalog release, the flaw was not listed in the Known Exploited Vulnerabilities catalog. That catalog was published before the CVE record, which went live early on 4 October (UTC).

Citrix credits Bishop Fox and watchTowr for working with it on the issue.

Why Last Week's Patch Is Not Enough

Bulletin CTX697096, published on 27 September, fixed eight flaws (CVE-2026-88771 to CVE-2026-88778). Citrix said exploitation of CVE-2026-88771 and CVE-2026-88772 had been observed. Its fixed builds were 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 FIPS/NDcPP. All of those are lower than the CVE-2026-88779 fix. Citrix's blog addresses this directly: if you upgraded to one of the builds from the CVE-2026-88771 to CVE-2026-88778 bulletin, and your deployment meets the SAML preconditions, "please upgrade your deployment again with the software released as part of the security bulletin for CVE-2026-88779."

Affected and Fixed NetScaler Builds

Release line27 Sept build (CTX697096)Affected by CVE-2026-88779Fixed build (CTX697174)
NetScaler ADC and Gateway 14.114.1-73.37Before 14.1-73.4114.1-73.41 and later
NetScaler ADC and Gateway 13.113.1-64.23Before 13.1-64.2813.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS14.1-73.37 FIPSBefore 14.1-73.41 FIPS14.1-73.41 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1-37.279Before 13.1-37.28213.1-37.282 and later

Citrix says Secure Private Access hybrid deployments that use NetScaler instances are also affected, and their NetScaler instances must be upgraded. The bulletin applies only to customer-managed appliances. Citrix upgrades its Citrix-managed cloud services, including Gateway Service and Citrix-managed Adaptive Authentication, itself.

Defensive Playbook for NetScaler Administrators

1. Determine exposure

From the NetScaler CLI, check the running build and whether either SAML precondition is present:

# Current firmware build
show version

# SAML SP / IdP preconditions named in CTX697174
show running config | grep -i "add authentication samlAction"
show running config | grep -i "add authentication samlIdPProfile"

If either line appears and the build is below the fixed version for its release line, the appliance is exposed.

2. Upgrade, even if you patched last week

Move to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP. Because these builds are newer than the CTX697096 builds, they also include last week's fixes. Upgrade HA pairs and every cluster node.

3. Use Global Deny List signatures as a bridge

Citrix has released Global Deny List signatures as an interim mitigation. According to Citrix, they need all of the following:

  • NetScaler Console, either on-premises with Cloud Connect or the Console service, with "Virtual patching" enabled.
  • A build in the range 14.1-73.37 up to (not including) 14.1-73.41, or 13.1-64.23 up to (not including) 13.1-64.28.

Citrix also says Global Deny List is enabled by default from 14.1-60.52 and 13.1-63.21. To verify:

# Signature version must be shown as a number, v24 or later, under "*Default Signatures"
show appfw signatures

# Confirm the deny-list rules are evaluating and hitting (Last Hit Time, counters > 0)
stat denylist global AAA_REQUEST

Citrix stresses that the signatures "can help to mitigate" the flaw but are not a replacement for upgrading.

4. Monitor and block

  1. Alert on unexpected NetScaler packet engine restarts, HA failovers or reboots on SAML-enabled appliances. These are the observable symptoms of a denial-of-service condition. (This is editorial guidance; Citrix has published no specific log signatures.)
  2. Citrix recommends using the NetScaler blocklist feature and perimeter firewall rules to block IP addresses identified as sources of attack activity.
  3. Follow your standard incident response process if you find signs of compromise. Given last week's actively exploited RCE pair, any appliance that ran pre-27 September builds while exposed to the internet deserves a forensic review, not just a firmware upgrade.