Vulnerability
Published 2026-10-03
Verified 2026-10-05

Citrix NetScaler CVE-2026-88779 (CVSS 8.7): SAML SP/IdP memory-overflow DoS — CTX697174 patches; CISA KEV due 7 Oct; ACSC AU impacts

Citrix Security Bulletin CTX697174 (published 3 Oct 2026; desk re-verified 5 Oct) assigns CVE-2026-88779 to the NetScaler SAML authentication crash/DoS tracked separately from CVE-2026-88771/88772. Description: memory overflow (CWE-119) leading to denial of service when NetScaler ADC or Gateway is configured as a SAML SP or SAML IdP. CVSSv4 base 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). Affected: NetScaler ADC/Gateway 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS/NDcPP before 13.1-37.282. Patch to: 14.1-73.41+, 13.1-64.28+, 14.1-73.41 FIPS+, 13.1-37.282+. CISA added CVE-2026-88779 to KEV on 4 Oct 2026 (due 7 Oct; forensic triage Yes; BOD 26-04). ASD's ACSC Critical alert (last updated 3 Oct) already flagged the SAML issue as separate from 88771/88772 and reported impacts to Australian organisations — confirm whether SAML Gateway/AAA config is present, apply CTX697174 builds, preserve ns.log/core/support bundle if crashed, and report to ASD's ACSC if impacted. Wire context (Cryptika/Heise 3 Oct): nsaaad crashes and pitboss reboots under crafted SAML traffic after 14.1-73.37 / 13.1-64.23. Distinct desk card citrix-netscaler-unpatched-rce-20260926 covers 88771/88772. UPDATE 5 Oct (SecurityWeek wire): researcher Kevin Beaumont, who calls the bug “PitScaler 2”, reports exploitation attempts against already-patched honeypots and says one honeypot ran a downloaded malware binary. Admins on Reddit shared logs showing SAML authentication requests with shell commands hidden in the username field that try to fetch and run a script; one admin who obtained the script says it tries to plant web shells, survive reboots and upload the appliance configuration and backups, but there is no proof it ran. SecurityWeek notes some indication the flaw may be usable beyond DoS; Citrix still says it has seen availability impact only and no data-integrity impact. Citrix credits Bishop Fox and watchTowr, and watchTowr says it reproduced the issue within hours of seeing honeypot activity (The Hacker News, 5 Oct).

Product
Citrix NetScaler ADC / NetScaler Gateway (customer-managed) configured as SAML SP or SAML IdP
Versions
14.1 before 14.1-73.41; 13.1 before 13.1-64.28; ADC FIPS before 14.1-73.41 FIPS; ADC FIPS/NDcPP before 13.1-37.282
CVSS
(CVSSv4 vendor — CVE-2026-88779)
Exploited in Australia?
unknown
Patch to
Upgrade to NetScaler ADC/Gateway 14.1-73.41+, 13.1-64.28+, 14.1-73.41 FIPS+, or 13.1-37.282+ per CTX697174. Confirm SAML SP/IdP (Gateway/AAA) config; if previously crashing, preserve ns.log, /var/core, auth records and a support bundle before restart; contact Citrix support and report to ASD's ACSC. Hunt authentication logs for usernames containing shell syntax (wget, curl, pipes, semicolons), check for new web shells, unexpected startup entries and outbound transfers of ns.conf or backups, and treat any hit as a compromise rather than a crash. Do not treat reboots alone as proof that CVE-2026-88771/88772 patches failed.

Primary: Citrix Security Bulletin CTX697174 — CVE-2026-88779 NetScaler SAML memory-overflow DoS (3 Oct 2026) · Vendor: ACSC Critical — Citrix NetScaler ADC/Gateway (Update 3 Oct 2026: SAML issue; AU impacts) · CVE: CVE-2026-88779, CVE-2026-88771 · CISA KEV — CVE-2026-88779 added 4 Oct 2026 (due 7 Oct; BOD 26-04 / forensic triage)

vulnerabilities australia network identity cloud