Skip to content
TrustList
News

NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28

Editorial

By TrustList Editorial

A new NetScaler flaw, CVE-2026-88779, affects Gateway and AAA deployments that use SAML and was exploited before a fix. Citrix says it is separate from last week's CTX697096 flaws; patched builds were released on 4 October.

About NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28

NetScaler SAML zero-day CVE-2026-88779: check Gateway and AAA SAML configurations and upgrade to 14.1-73.41 or 13.1-64.28

4 October 2026 — A week after the CTX697096 flaws, NetScaler administrators face another weekend emergency. Citrix's NetScaler threat-intelligence team published guidance on 3 October 2026 about a newly observed issue in customer-managed NetScaler deployments that use SAML authentication with Gateway or AAA. A security bulletin followed early on 4 October, assigning CVE-2026-88779, according to heise online, which reports that an exploit was already circulating and that patched builds were released over the weekend.

Not yet independently verified. Citrix's own guidance post confirms the issue and the affected SAML configurations. The CVE number, the CVSS 8.7 rating and the fixed builds come from heise's report of Citrix's security bulletin, which we could not open at 2026-10-04. Exploitation is reported by heise and security researchers; Citrix's post speaks of customers experiencing impact. We will update this when it can be confirmed, and remove this note.

What is affected

Citrix says the issue depends on configuration. A NetScaler is affected when it acts as a Gateway or AAA virtual server and its configuration contains at least one of these commands:

  • add authentication samlAction
  • add authentication samlIdPProfile

In other words, appliances set up as a SAML service provider or SAML identity provider. Citrix states that the issue is independent of the vulnerabilities in bulletin CTX697096 (CVE-2026-88771 and CVE-2026-88772), which we covered last week. A security researcher quoted by heise suggests it may be a way around that earlier fix; Citrix has not said so.

heise describes CVE-2026-88779 as a buffer overflow rated 8.7 on CVSS 4, which can crash an appliance or allow code to be run, and reports that it can be triggered by sending large numbers of SAML requests. Administrators on Citrix's forums and elsewhere have reported appliances rebooting under scans.

Fixed builds

According to heise's report of the bulletin, the fixed builds are:

  • NetScaler ADC and Gateway 14.1-73.41 and later
  • 13.1-64.28 and later
  • 14.1-73.41 FIPS and later
  • 13.1-37.282 and later of 13.1-FIPS and 13.1-NDcPP

What to do

  1. Search every NetScaler configuration for the two SAML commands above. If neither is present, Citrix's guidance indicates the appliance is not exposed to this issue, though last week's patches still apply.
  2. If either is present, upgrade to a fixed build now. Confirm the exact builds against Citrix's own bulletin before you schedule the change.
  3. If appliances are crashing or rebooting, contact Citrix support, as Citrix advises, and preserve logs before rebooting.
  4. Treat any appliance that was exposed and unpatched as possibly compromised: review sessions, new admin accounts and outbound connections.
  5. Subscribe to Citrix security bulletin alerts, since guidance on this issue is still being updated.

Why it matters for buyers

NetScaler sits at the edge of many corporate networks and carries single sign-on for remote staff. Two serious flaws in two weeks, each exploited before most customers could patch, is a reason to review how quickly your team can patch edge appliances over a weekend, and whether a managed or cloud-delivered alternative would shift that burden.

Sources

Categories & features