Citrix has released emergency security updates for the actively exploited NetScaler zero-day vulnerability CVE-2026-88779. The flaw affects certain customer-managed NetScaler ADC and NetScaler Gateway appliances that use SAML authentication with Gateway or AAA functionality.
What happened
Citrix says CVE-2026-88779 is a memory buffer vulnerability with a CVSS v4.0 score of 8.7. The company has observed targeted attacks against unmitigated deployments that can cause denial-of-service conditions. Repeated exploitation may leave the affected service unavailable.
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities Catalog on October 4, 2026, confirming evidence of active exploitation. Federal civilian agencies were directed to mitigate the vulnerability by October 7, 2026.
What is confirmed
Citrix confirmed targeted attacks and released fixed NetScaler builds. The company says its current analysis shows an impact to service availability and that it has not identified an impact on customer-data integrity.
Affected supported versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41, version 13.1 before 13.1-64.28, NetScaler ADC 14.1 FIPS before 14.1-73.41 FIPS, and NetScaler ADC 13.1 FIPS or NDcPP before 13.1-37.282.
What remains unverified
Security researchers are investigating reports that attack activity may extend beyond denial of service. Public reports describe suspicious payload-download attempts and malware activity on honeypots, but Citrix has not confirmed remote code execution through CVE-2026-88779. Organizations should not treat those reports as confirmed vendor findings.
Who is affected
The issue applies to customer-managed NetScaler deployments when SAML authentication is configured with Gateway or AAA functionality. Citrix-managed cloud services are being updated by Citrix and are not covered by the customer-managed appliance bulletin.
Administrators can review configurations for add authentication samlAction or add authentication samlIdPProfile entries to determine whether the required SAML preconditions are present.
Why this matters
NetScaler appliances commonly sit at the network edge and support remote access and authentication. A sustained service outage can interrupt employee access, customer-facing services, and business operations. Organizations that recently patched other NetScaler vulnerabilities may need to upgrade again because the newly released builds contain the CVE-2026-88779 fix.
Practical defensive actions
Install the fixed release
Upgrade affected appliances to NetScaler 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 for FIPS and NDcPP deployments, as applicable. Confirm the installed build after the maintenance window.
Check SAML exposure
Review Gateway and AAA configurations for the SAML actions identified by Citrix. Prioritize internet-facing appliances and systems supporting remote access.
Use temporary protections without delaying updates
Citrix provides Global Deny List signatures that can reduce exposure for supported configurations. The vendor states that this is a mitigation and still recommends installing the fixed software as soon as possible.
Review logs and begin incident response if needed
Investigate unexplained authentication-service crashes, repeated appliance reboots, unusual SAML requests, suspicious shell-command strings, outbound connections, and unexpected files or processes. Preserve logs and system evidence before rebuilding or restoring an appliance.
Sources
Citrix security bulletin CTX697174
Citrix technical guidance for CVE-2026-88779