Skip to finding
§
High
Edge
Confirmed
CVE-2026-88779

September’s emergency NetScaler fixes did not eliminate repeatable unauthenticated SAML outages.

Citrix reports targeted attacks, and CISA has added the flaw to its exploited-vulnerability catalog.

Affects

Customer-managed NetScaler ADC and NetScaler Gateway appliances providing application delivery, AAA and remote-access VPN services.

What it enables

Unauthenticated persistent denial of service against SAML authentication gateways

Reach an affected Gateway or AAA virtual server configured to use NetScaler as a SAML SP or IdP.→↓Send traffic that triggers the SAML-path memory overflow and crashes the service.→↓Repeat the trigger to keep the authentication or remote-access service unavailable.
Why this matters

An unauthenticated client can still repeatedly crash SAML-enabled NetScaler gateways after the emergency fixes, and Citrix reports attacks against unmitigated deployments.

Detail and 2 sources
Required access

Unauthenticated network reachability to a Gateway or AAA virtual server using NetScaler as a SAML service provider or identity provider

Affected versions

NetScaler ADC and Gateway 14.1 before 14.1-73.41, NetScaler ADC and Gateway 13.1 before 13.1-64.28, NetScaler ADC 14.1-FIPS before 14.1-73.41-FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282

An unauthenticated client can reach the memory-overflow path on a Gateway or AAA virtual server where NetScaler acts as a SAML service provider or identity provider, then repeat the trigger to keep the service unavailable.

Citrix has not identified an integrity impact, and reports calling the flaw remote code execution remain unconfirmed.

Evidence
Citrix confirms targeted attacks against unmitigated deployments and a denial-of-service consequence.Citrix says repeated triggering may keep the service unavailable.Citrix has not identified an integrity impact; reports characterizing the flaw as RCE remain unconfirmed.CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026