CVE-2026-88779: Citrix Calls It Denial of Service. Researchers See Signs of Code Execution
Citrix calls CVE-2026-88779 a NetScaler denial of service, but admins logged shell commands in SAML login requests and a patched honeypot ran a malware binary. Citrix has not confirmed code execution. Appliances with the earlier fixes need this update too.

Citrix released emergency updates on October 4, 2026 for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway that attackers were already using against unmitigated appliances. Citrix rates it CVSS 8.7 and describes the impact as denial of service, with no impact on the integrity of customer data identified. Administrators and researchers have reported more than crashes, including shell commands inside SAML login requests and a malware binary running on a patched honeypot. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, with a federal deadline of October 7.
How the SAML Memory Overflow Works
CVE-2026-88779 is tracked as CWE-119, improper restriction of operations within the bounds of a memory buffer. It only matters on appliances configured as a SAML service provider or SAML identity provider, which means Gateway or AAA virtual servers that handle SAML logins. An attacker reaches it over the network with no credentials and no user interaction, and Citrix's CVSS 4.0 vector scores the impact on availability only. In practice a crafted authentication request overflows a buffer and crashes the authentication service. NetScaler's Pitboss watchdog then restarts the service or reboots the appliance, and repeated requests keep it unavailable. Neither Citrix nor watchTowr has published technical details of the overflow, although watchTowr says it has reproduced the bug.
Who's Affected
Customer-managed NetScaler ADC and NetScaler Gateway appliances are affected when they run a build older than 14.1-73.41 on the 14.1 branch or older than 13.1-64.28 on the 13.1 branch. NetScaler ADC FIPS and NDcPP builds are affected before 14.1-73.41 FIPS and 13.1-37.282. Secure Private Access Hybrid deployments that use affected NetScaler instances need the update too, while Cloud Software Group handles Citrix-managed cloud and Adaptive Authentication. To check exposure, look for add authentication samlAction (SAML service provider) or add authentication samlIdPProfile (SAML identity provider) in the running configuration. Either line puts the appliance in scope, and neither is evidence of compromise. VulnTracker shows the NVD status as Received with no CPE data yet, so the vendor bulletin is the reliable source for version ranges.
Denial of Service on Paper, Something Else in the Logs
Citrix's bulletin stops at availability. The field evidence points further. An administrator running build 14.1-73.37, which carried the previous round of NetScaler fixes, found authentication requests with shell commands in the username field that told the appliance to download a payload from an outside IP address and run it. Those requests landed right before confirmed crashes, though the logs did not show that the commands actually executed. Researcher Kevin Beaumont then reported that one of his patched honeypots was running a downloaded malware binary, and watchTowr said it had reproduced the flaw. SecurityWeek relays an allegedly captured script that tried to plant web shells, survive reboots, and upload the appliance configuration and backups, with execution still unproven. None of this changes Citrix's official position. It does match the history: CVE-2025-6543 was first described as a denial of service before attacks showed it could execute code. Until Citrix or the researchers say otherwise, treat a crash on a SAML appliance as a possible intrusion and check it for payload activity.
Reading It on VulnTracker
The CVE-2026-88779 page on VulnTracker shows the 8.7 High score from NetScaler under CVSS 4.0, an Actively Exploited banner from the CISA KEV catalog, and a remediation deadline of October 7. EPSS sits at 0.3 percent, higher than 18 percent of all CVEs. SSVC marks exploitation as Active and automatable with partial impact, which fits a bug that anyone can trigger repeatedly over the network. The CWE tag is CWE-119. The Affected Platforms table is empty because NVD has not analyzed the record yet, and the Affected Products list names Gateway and ADC without usable version data, so use the ranges in the description for scoping. Track the CVE to catch NVD enrichment and any change to Citrix's impact statement.
What to Do Now
First confirm whether SAML is in play by searching every admin partition for samlAction and samlIdPProfile entries. If either exists, upgrade to 14.1-73.41 or later on the 14.1 branch, 13.1-64.28 or later on 13.1, 14.1-73.41 FIPS on FIPS builds, or 13.1-37.282 on 13.1 FIPS and NDcPP. This applies even if you installed the fixes from the earlier NetScaler bulletin, because Citrix says appliances that took those releases must upgrade again. Citrix is also publishing Global Deny Lists of known malicious IP addresses, which helps and does not replace the update. Then look back. Search authentication logs for usernames that contain shell syntax, check for unexplained service crashes and appliance reboots, and review outbound connections from the appliance. If you find a downloaded payload or an unexpected process, treat the appliance as compromised: capture a forensic image, rotate the credentials and secrets stored on it, and rebuild it rather than clean it. Federal agencies must mitigate by October 7, 2026 under BOD 26-04, a sensible target for everyone else too.
CVE-2026-88779 shows how little a vendor's severity label settles while attacks are still being studied. If a SAML-enabled NetScaler sits at your edge, patch it now even if it already carries the last round of fixes, and read its logs as if someone has been testing it. Track CVE-2026-88779 on VulnTracker to see how the impact assessment changes as researchers publish.
References
Citrix bulletin CTX697174 · NVD entry for CVE-2026-88779 · BleepingComputer · SecurityWeek · Cyber Security News