NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28
EditorialBy TrustList Editorial
A new NetScaler flaw, CVE-2026-88779, affects Gateway and AAA deployments that use SAML and was exploited before a fix. Citrix says it is separate from last week's CTX697096 flaws; patched builds were released on 4 October.
- United States
- Fort Lauderdale, Fl
- Florida
- Cybersecurity
- +4 more
About NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28
NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28
4 October 2026 — A week after the CTX697096 flaws, NetScaler administrators face another weekend emergency. Citrix's NetScaler threat-intelligence team published guidance on 3 October 2026 about a newly observed issue in customer-managed NetScaler deployments that use SAML authentication with Gateway or AAA. A security bulletin followed early on 4 October, assigning CVE-2026-88779, according to heise online, which reports that an exploit was already circulating and that patched builds were released over the weekend.
Not yet independently verified. Citrix's own guidance post confirms the issue and the affected SAML configurations. The CVE number, the CVSS 8.7 rating and the fixed builds come from heise's report of Citrix's security bulletin, which we could not open at 2026-10-04. Exploitation is reported by heise and security researchers; Citrix's post speaks of customers experiencing impact. We will update this when it can be confirmed, and remove this note.
What is affected
Citrix says the issue depends on configuration. A NetScaler is affected when it acts as a Gateway or AAA virtual server and its configuration contains at least one of these commands:
add authentication samlActionadd authentication samlIdPProfile
In other words, appliances set up as a SAML service provider or SAML identity provider. Citrix states that the issue is independent of the vulnerabilities in bulletin CTX697096 (CVE-2026-88771 and CVE-2026-88772), which we covered last week. A security researcher quoted by heise suggests it may be a way around that earlier fix; Citrix has not said so.
heise describes CVE-2026-88779 as a buffer overflow rated 8.7 on CVSS 4, which can crash an appliance or allow code to be run, and reports that it can be triggered by sending large numbers of SAML requests. Administrators on Citrix's forums and elsewhere have reported appliances rebooting under scans.
Fixed builds
According to heise's report of the bulletin, the fixed builds are:
- NetScaler ADC and Gateway 14.1-73.41 and later
- 13.1-64.28 and later
- 14.1-73.41 FIPS and later
- 13.1-37.282 and later of 13.1-FIPS and 13.1-NDcPP
What to do
- Search every NetScaler configuration for the two SAML commands above. If neither is present, Citrix's guidance indicates the appliance is not exposed to this issue, though last week's patches still apply.
- If either is present, upgrade to a fixed build now. Confirm the exact builds against Citrix's own bulletin before you schedule the change.
- If appliances are crashing or rebooting, contact Citrix support, as Citrix advises, and preserve logs before rebooting.
- Treat any appliance that was exposed and unpatched as possibly compromised: review sessions, new admin accounts and outbound connections.
- Subscribe to Citrix security bulletin alerts, since guidance on this issue is still being updated.
Why it matters for buyers
NetScaler sits at the edge of many corporate networks and carries single sign-on for remote staff. Two serious flaws in two weeks, each exploited before most customers could patch, is a reason to review how quickly your team can patch edge appliances over a weekend, and whether a managed or cloud-delivered alternative would shift that burden.
Sources
Categories & features
- United States
- Fort Lauderdale, Fl
- Florida
- Cybersecurity
- Vulnerability Management
- Patch Management
- Remote Access
- Single Sign On
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.