Home/ Blog/ Security news/ Article
Blog · Security news

NetScaler CVE-2026-88779: Pre-Auth DoS in SAML Setups, Patch Now

Citrix NetScaler CVE-2026-88779 lets an unauthenticated attacker crash ADC and Gateway appliances configured for SAML sign-on. Patch to 14.1-73.41 now.

Lone lighthouse at night with a dark lamp room and a hairline crack up its shaft

An unauthenticated attacker can knock a Citrix NetScaler appliance offline, and the only precondition is a sign-on configuration that most enterprises already run. Citrix published advisory CTX697174 on October 3, 2026 for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway that leads to denial of service (DoS), the class of flaw that forces a device to stop serving traffic rather than leak or run code. The fix is already shipping: upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS builds. What makes this one worth your attention is who it hits and when it landed.

It landed days after two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, that CISA confirmed as actively exploited and added to its Known Exploited Vulnerabilities catalog. We walked through that pair and the hunt that follows a patch in our coverage of CVE-2026-88772. This new flaw is a quieter bug than those, but it hits the same boxes, and for a lot of teams it hits the same configuration.

What CVE-2026-88779 breaks

The CVE record rates it CVSS 8.7 (version 4.0) and classes it as a memory buffer flaw (CWE-119). Read the vector and the scope is narrow in one way and wide in another. The attack needs no authentication, no user interaction, and only network access with low complexity, so anyone who can reach the appliance can try it. But the only impact is availability: no confidentiality loss, no integrity loss, no code execution in the published assessment. In plain terms, a crafted request can crash the appliance, not steal from it.

That is why this is a High, not a Critical, and why it reads as an afterthought next to last week's remote code execution zero-days. For most of the internet that framing is correct. For anyone who routes remote access through a NetScaler Gateway, it is not. A DoS on the box that terminates your SSL VPN and brokers your logins is not a side issue, it is your entire remote workforce locked out until the appliance comes back. Availability is the whole job of an edge gateway, and this bug attacks exactly that.

Who is actually in scope

This does not affect every NetScaler. Per CTX697174, the flaw only applies when the appliance is configured as a SAML Service Provider (the add authentication samlAction directive) or a SAML Identity Provider (add authentication samlIdPProfile). SAML, short for Security Assertion Markup Language, is the standard protocol enterprises use to broker single sign-on between an application and an identity provider such as Entra ID or Okta. If your Gateway or AAA virtual server hands users off to a corporate identity provider, that is almost certainly a SAML Service Provider setup, and that is the population in scope.

Here is the uncomfortable overlap. The deployments most likely to run SAML on NetScaler, authenticating gateways in front of an enterprise identity provider, are the same deployments that threat actors just spent a week probing for the 88771 and 88772 zero-days. The attackers already know these boxes are exposed and worth hitting. A pre-auth crash is a weaker primitive than pre-auth code execution, but it is a cheap follow-up against a target set that is already mapped.

Before you triage, find out whether you are even in scope. The precondition is checkable from the appliance's own running configuration.

/nsconfig/ns.conf - is this appliance in scope for CVE-2026-88779?
grep -E "add authentication (samlAction|samlIdPProfile)" /nsconfig/ns.conf

A non-empty result means the appliance runs SAML as a Service Provider or Identity Provider and is affected. An empty result is not a reason to skip the upgrade, it only tells you the clock is less urgent, because the next NetScaler advisory will land on a different feature.

The build you rushed to last week is already behind

Teams that scrambled for the zero-days patched to 14.1-73.37 or 13.1-64.23 about a week ago. CVE-2026-88779 is fixed in 14.1-73.41 and 13.1-64.28, newer builds than the ones most of them stopped at. So the appliance you declared patched on one Monday is out of date by the next. That is the pattern worth naming on edge gear: the known-good version is not a fixed target you reach once, it is a number that moves every time the vendor ships, and NetScaler has been shipping often.

The operational fix is to stop treating the build string as a milestone and start treating it as a tracked asset, the same way you track which hosts are missing a patch. Knowing, on any given morning, which of your edge appliances is running which build is a vulnerability-detection problem, not a one-time change ticket. This is the second memory-handling flaw we have covered on this platform this year, after the HTTP/2 memory leak in a prior NetScaler batch, and the lesson repeats: the gateway guarding the door keeps turning out to be the thing that breaks.

Check for SAML sign-on, then upgrade to 14.1-73.41

Run the configuration check above first so you know your exposure. If SAML Service Provider or Identity Provider is present, move this appliance to the front of the queue and upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS build without waiting for a routine window. If it is not present, schedule the upgrade anyway on your normal edge cadence. There is no mitigation short of patching, and no exploit or in-the-wild activity has been reported for CVE-2026-88779 as of publication, which is the good news and the reason to move now rather than after one appears.

On the detection side, availability flaws leave their evidence in uptime, not in access logs. Watch for unexplained NetScaler packet-engine restarts and gateway outages in your monitoring, and treat a crash on a SAML-configured box as a possible exploitation attempt rather than a glitch. Appliances in front of identity have been this quarter's recurring soft spot, a pattern we traced in our Signal piece on identity appliances getting bypassed.

Topics

Frequently asked questions

What is CVE-2026-88779?

CVE-2026-88779 is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker crash the appliance, a denial of service. Citrix rates it CVSS 8.7 and fixed it in advisory CTX697174, published October 3, 2026.

Which NetScaler appliances are affected?

Only appliances configured as a SAML Service Provider or SAML Identity Provider are affected. That covers most Gateway and AAA deployments that broker single sign-on to a corporate identity provider. Check your running config for the samlAction or samlIdPProfile directives to confirm.

Is CVE-2026-88779 being exploited?

No public exploit or in-the-wild exploitation has been reported for CVE-2026-88779 as of publication. That is different from the NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which CISA confirmed as actively exploited days earlier.

Which NetScaler version fixes CVE-2026-88779?

Upgrade to NetScaler ADC and Gateway 14.1-73.41 or 13.1-64.28, the 14.1-73.41 FIPS build, or the 13.1-37.282 FIPS and NDcPP build. These are newer than the 14.1-73.37 and 13.1-64.23 builds that fixed the earlier zero-days.

Can I mitigate CVE-2026-88779 without patching?

Citrix lists no workaround other than upgrading. If you cannot patch immediately, confirm whether SAML Service Provider or Identity Provider is configured, since appliances without it are out of scope, and monitor the box for unexplained restarts that could signal a crash attempt.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.