Attackers Are Crashing Citrix NetScaler Gateways That Use SAML Sign-In — Upgrade Again, Even If You Just Patched

A memory flaw lets an unauthenticated attacker knock NetScaler's SAML sign-in offline. Citrix has seen targeted attacks and CISA added it to KEV on October 4.

Get Advisory Support
High CVE-2026-88779

CVE-2026-88779 is a memory overflow flaw, rated 8.7 (high) under CVSS v4.0, in Citrix NetScaler ADC and NetScaler Gateway, the appliances many organizations use for remote access, VPN and single sign-on. It can be triggered over the network without a login, and it only affects appliances configured as a SAML service provider or SAML identity provider. Citrix says the result is a denial of service: if the attack is repeated, the service may stay unavailable, which can cut off remote access for an entire organization.

Affected customer-managed releases are NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, NetScaler ADC FIPS before 14.1-73.41 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.282. Citrix published its security bulletin on October 3, 2026, and notes that customers who just upgraded for the earlier bulletin covering CVE-2026-88771 through CVE-2026-88778 must upgrade again if they use SAML. Citrix-managed cloud services are updated by Citrix.

Citrix states it has observed targeted attacks on unmitigated deployments, and CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4, 2026, with a federal deadline of October 7. Citrix says it has not identified an impact on the integrity of customer data, although some researchers quoted by BleepingComputer report attackers running downloaded malware on research decoy systems; Citrix has not confirmed that.

Recommended action: If you run NetScaler ADC or Gateway yourself, check this week whether it uses SAML: look in the configuration for 'add authentication samlAction' or 'add authentication samlIdPProfile'. If either is present, upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP) or later, even if you upgraded in the past few days. Until you can, use the Global Deny List signatures Citrix released through NetScaler Console, and confirm they are active with 'stat denylist global AAA_REQUEST'. Review logs for unexpected reboots or authentication-service crashes since early October, and block source addresses of attack traffic at the firewall. Because remote access to clinical systems, patient records or municipal services often runs through this gateway, plan for an outage: confirm staff have a backup way to reach critical systems. If a managed service provider runs your NetScaler, ask them in writing which build you are on and whether SAML is configured.

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check