NetScaler CVE-2026-88779: an unauthenticated DoS crashing SAML gateways
NetScaler CVE-2026-88779 is an unauthenticated memory-overflow DoS crashing SAML gateways, exploited in the wild. Fixed builds, KEV deadline, triage.
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
A week after Citrix shipped emergency patches for two NetScaler remote-code-execution zero-days, the same product line is back on the CISA Known Exploited Vulnerabilities catalog — this time for a bug that steals nothing and runs no code. CVE-2026-88779 is a memory-overflow flaw that an unauthenticated attacker can trigger over the network to knock a NetScaler Gateway offline and keep it there. Citrix says it is already being used in targeted attacks. For an appliance whose entire job is to be the remote-access and single-sign-on front door, "merely" a denial of service is not a small story.
Developing story — first published 21:44 CEST (19:44 UTC), October 4, 2026. Updated as the vendor and CISA publish more.
At a glance
| CVE | CVE-2026-88779 |
| Product / affected versions | NetScaler ADC & Gateway 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS/NDcPP before 13.1-37.282 |
| Fixed in | 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282 (FIPS/NDcPP) · advisory CTX697174, published 2026-10-03 PST |
| CVSS | 8.7 High · CVSS 4.0 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N · scored by Citrix (CNA); NVD mirrors 8.7 |
| Exploited in the wild | Yes · Citrix has observed targeted attacks; CISA KEV-listed |
| CISA KEV | Added 2026-10-04; federal due date 2026-10-07 (BOD 26-04, forensic triage required) |
| Official advisory | Citrix bulletin CTX697174 |
What CVE-2026-88779 actually breaks
The vulnerability is an improper restriction of operations within the bounds of a memory buffer (CWE-119) — a memory overflow that an attacker reaches with a crafted request requiring no credentials and no user interaction. The CVSS 4.0 vector tells the whole story in its impact metrics: VC:N/VI:N/VA:H. Confidentiality impact none, integrity impact none, availability impact high. This is not a data-theft bug and it is not code execution. It is a way to make the box fall over.
That matters because it is the opposite of the two NetScaler zero-days from the previous weekend. CVE-2026-88771 and CVE-2026-88772 were unauthenticated remote code execution — an attacker owning the appliance. CVE-2026-88779 gives the attacker no foothold at all. What it gives them is an off switch. Per the vendor, "if the condition is triggered repeatedly, the service may remain unavailable" — so this is not a one-shot crash you reboot past; it is a sustained outage for as long as the attacker keeps sending traffic.
Who is exposed: the SAML precondition
Unlike the RCE pair, which affected essentially every deployment in a default configuration, CVE-2026-88779 has a precondition. The appliance is only exposed if it is configured for SAML authentication — acting as a SAML Service Provider or SAML Identity Provider on a Gateway or AAA virtual server. If your NetScaler does not do SAML, this specific bug does not reach you.
Do not read that as "most of us are safe." SAML is how NetScaler Gateway brokers single sign-on into the enterprise — it is the component that federates remote-access logins to an identity provider and onward to SaaS. On a large share of real deployments, SAML on a Gateway or AAA vserver is the configuration. Check it directly rather than assuming:
Does
show authentication samlAction(orshow authentication samlIdPProfile) return a profile bound to a Gateway or AAA virtual server? If yes, and your build is below the fixed version in the table above, you are in scope.
The affected-versions list is identical across the ADC and Gateway product names and spans the current 14.1 and 13.1 trains plus the FIPS and NDcPP variants. There is no "we only run ADC, not Gateway" exemption — the ADC load-balancing SKU can carry the same vulnerable SAML code paths.
Why a denial of service on this box is a security incident
It is tempting to file a DoS below an RCE and move it down the queue. For this asset, that instinct is wrong, for three reasons.
- The box is the control point for remote access. When the NetScaler Gateway is down, your remote workforce, your VPN, and often your SAML-brokered SaaS logins are down with it. An attacker who can hold it offline on demand has an availability weapon pointed at the thing that lets everyone in.
- A reliable outage is a cover story. A gateway that is crash-looping generates exactly the noise — reboots, failed-auth storms, help-desk tickets — under which other activity hides. The hard part of incident response is not seeing the crash; it is proving the crash was the whole event and not a distraction running alongside something quieter.
- CISA requires forensic triage anyway. The KEV entry for CVE-2026-88779 is flagged for forensic triage, with a federal due date of 2026-10-07 under BOD 26-04. The directive does not let you treat a confirmed-exploited KEV bug as a simple reboot, even when the rated impact is availability only.
Remediation
1. Am I affected? Confirm the SAML precondition and the build. On the NetScaler CLI, check for a SAML action or IdP profile bound to a Gateway/AAA vserver (show authentication samlAction, show authentication samlIdPProfile, show authentication vserver). Confirm the firmware with show ns version. In scope = SAML SP/IdP configured and a build below the fixed version.
2. Patch — exact fixed builds. There is no workaround; upgrading is the only fix. Per Citrix CTX697174:
| Train | Fixed build |
|---|---|
| 14.1 | 14.1-73.41 and later |
| 13.1 | 13.1-64.28 and later |
| 14.1 FIPS | 14.1-73.41 FIPS and later |
| 13.1 FIPS / NDcPP | 13.1-37.282 and later |
Appliances on 12.1 and 13.0 are end-of-life and receive no fix — they must be migrated to a supported train.
3. Can't patch this minute? Citrix offers no supported mitigation for CVE-2026-88779, so compensating controls are stopgaps only, not a substitute for the upgrade. If SAML is genuinely unused on a given vserver, removing the SAML action binding removes the precondition. Where SAML is in use, the realistic stopgap is restricting who can reach the authentication endpoint — upstream ACLs or a filtering layer in front of the Gateway — while you schedule the upgrade inside the KEV window.
4. Hunt for compromise. Treat the outage as an event to be reconstructed, not just recovered from. The attacker's access vector is the public-facing service (T1190) and the effect is endpoint denial of service (T1499). Pull the authentication and ns.log history across the crash window and ask whether the reboots line up with a burst of anomalous unauthenticated requests to the SAML endpoint, and whether anything else touched the appliance or the internal network while it was flapping. A rooted or previously-compromised appliance can rewrite its own on-box logs, so corroborate against upstream network records rather than trusting the box's account of its own crash.
5. Eradicate + verify. After upgrading, confirm the service is stable under the same conditions that triggered the outage, and — because this product line has been breached repeatedly in 2026 — verify that no session, key, or configuration artifact from an earlier incident is still live. Patching ends this DoS; it does not by itself prove the appliance is clean.
What is not known yet
- Who is behind the targeted attacks. Citrix confirms exploitation but has not attributed it; no actor or campaign name is public as of this writing.
- Whether exploitation is purely disruptive. The rated impact is availability only, and nothing published suggests code execution via this CVE — but whether the outages are an end in themselves or cover for concurrent activity is exactly what per-victim triage has to establish.
- The exploited population size. There is no public count of affected or attacked appliances, and NVD still lists the record as freshly received, so its enrichment (CPE set, formal SSVC) may change.
This section will be updated as the vendor, CISA, and researchers publish more.
Where Zero Hunt fits
The operational question CVE-2026-88779 forces is not "what did they steal" but "is this crash an attack, and is it the only thing happening right now." That is a traffic question before it is a log question. Zero Hunt's AI Traffic Analysis runs a proprietary deep-learning model with four parallel inference heads — suspicious traffic, malware classification, attack-type identification, application fingerprinting — on the appliance GPU at a 2.7+ Gbit/s baseline, trained on billions of PCAP sequences, entirely on-premise. It profiles what normal looks like in front of your NetScaler, so a burst of malformed unauthenticated requests to the SAML endpoint and the crash-loop they induce read as a targeted availability attack while it is happening, not as a flaky appliance you reboot and forget — and, just as important, it keeps watching for the quieter traffic that a convenient outage is designed to mask.
Answering the other half — "is my edge even exposed to this" — is where the autonomous red team comes in. Zero Hunt is an on-premise AI red team running its own private models, with a human in the loop for every action that matters. A version string tells you the build; it does not tell you whether an attacker can reach the SAML path on your topology, or whether the upgrade actually closed it. The 10-agent swarm answers that against your real deployment — black-box by default — and a change-triggered campaign re-runs the proof within the hour whenever a new appliance appears on the perimeter. Because a gateway outage is itself a reportable service disruption under regimes like NIS2 Article 23, which counts from the moment you become aware, every finding is signed at write time (Ed25519, hash-chained) so the evidence of what happened — and when you knew — exists before anyone asks for it.
Every vulnerability CISA lists as exploited, with federal due dates: CISA KEV tracker →
Is this exploitable in your environment?
Zero Hunt answers that on your own network: an autonomous AI red team on an on-premise appliance, running on private AI, black-box or gray-box, with a human approving every step that matters. Proof of what is exploitable, the fix, and signed evidence — no data leaves your perimeter.