NetScaler SAML zero-day CVE-2026-88779: what fixes it
A NetScaler SAML zero-day, CVE-2026-88779, is under attack and last week's patch misses it. Who is exposed, the fixed builds and the October 7 deadline.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

A new NetScaler SAML zero-day, CVE-2026-88779, is being exploited against Citrix NetScaler ADC and NetScaler Gateway appliances that sign users in with SAML, and the fix is build 14.1-73.41 or 13.1-64.28 or later. If you patched last week for CVE-2026-88771, that build does not cover this flaw. This guide shows how to tell whether your appliance is exposed, which builds fix it, and what the October 7 federal deadline means.
Key takeaways
- Only SAML setups are affected: Citrix's bulletin, published October 3, 2026, says the flaw hits appliances configured as a SAML service provider (SP) or SAML identity provider (IdP). It scores 8.7 on CVSS v4.
- Exploitation is confirmed by CISA: the agency added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4 and gave US federal agencies until October 7 to act.
- Last week's builds are not enough: 14.1-73.37 and 13.1-64.23 fixed CVE-2026-88771, but Tenable notes a SAML-configured appliance on those builds is still vulnerable. You need 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS and NDcPP), or later.
- Citrix calls it denial of service. Reports of code execution so far come from an administrator and a security researcher, not from Citrix, and remain unconfirmed as of October 5.
What the NetScaler SAML zero-day is
Citrix security bulletin CTX697174 describes CVE-2026-88779 as a "memory overflow vulnerability leading to Denial of Service," a buffer flaw classed as CWE-119. Its CVSS v4 vector rates the impact on availability as high and the impact on confidentiality and integrity as none. Citrix "strongly urges" affected customers to install the updated builds as soon as possible and lists no workaround.
SAML (Security Assertion Markup Language) is the standard that lets an appliance hand sign-in to an identity provider, or act as one. The bulletin names two configurations that make an appliance vulnerable:
- SAML service provider: the configuration contains
add authentication samlAction. - SAML identity provider: the configuration contains
add authentication samlIdPProfile.
Citrix adds that Secure Private Access hybrid deployments that run on NetScaler instances are affected too.
The bulletin itself does not describe attacks. Citrix's own statement, as quoted by BleepingComputer, says it "has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service." The Hacker News reports that Citrix says the issue affects service availability and that it has not identified an impact on the integrity of customer data.
Is it only a denial of service?
That is Citrix's classification, and it is the only one on the record from the vendor. Two reports point further, and neither is confirmed:
- An administrator's logs. BleepingComputer reports that one NetScaler admin found malicious login requests with shell commands embedded in the username field, which downloaded a payload, saved it and ran it. The admin tied the requests to crashes of the
nsaaadauthentication process but stressed that exploitation was not confirmed. - A honeypot. BleepingComputer also reports that security researcher Kevin Beaumont saw one of his patched honeypots running downloaded malware, which would suggest code execution rather than a crash alone.
The Hacker News adds that watchTowr said it reproduced the flaw within hours. For planning, treat this as more than an outage risk: if code execution is possible, a crash in your logs could be the visible part of an intrusion.
Why last week's patch doesn't cover it
On September 27, Citrix's bulletin CTX697096 fixed eight flaws, including the exploited CVE-2026-88771 and CVE-2026-88772, in builds 14.1-73.37 and 13.1-64.23. We covered that round in our guide to the earlier NetScaler zero-days.
CVE-2026-88779 is a separate bug with its own bulletin. Tenable's FAQ is explicit: organizations whose appliances are configured for SAML need the newer builds released October 3. An appliance you upgraded last week is fully patched for the September flaws and still exposed to this one if it uses SAML.
| Branch | Fixes CVE-2026-88771 (Sept 27) | Fixes CVE-2026-88779 (Oct 3) |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 | 14.1-73.41 or later |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 | 13.1-64.28 or later |
| NetScaler ADC 14.1 FIPS | 14.1-73.37 FIPS | 14.1-73.41 FIPS or later |
| NetScaler ADC 13.1 FIPS and NDcPP | 13.1-37.279 | 13.1-37.282 or later |
The newer builds are later releases on the same branches, so moving to them keeps last week's fixes.
Step 1: Check whether your appliance uses SAML
Search each appliance's running or saved configuration for the two commands from Citrix's bulletin: add authentication samlAction and add authentication samlIdPProfile. A match on either means the appliance is in scope. On a Gateway, SAML is common when users sign in through an outside identity provider, so don't assume you're clear because the appliance "only" does VPN.
Do this on every appliance, including disaster recovery pairs and test boxes that face the internet. An appliance with no SAML configuration is outside this bulletin, but it still needs the September builds for CVE-2026-88771.

Step 2: Find the build each appliance runs
Compare each appliance's build, shown in the management interface or with show ns version in the CLI, against the table above. Anything below 14.1-73.41 on 14.1, or below 13.1-64.28 on 13.1, is vulnerable when SAML is configured. FIPS and NDcPP appliances need their own builds, not the standard ones.
The bulletin lists only the 14.1 and 13.1 branches. Our earlier guide notes that 12.1 and 13.0 are end of life and get no fixes, so an appliance on either needs a move to a supported branch.
Step 3: Look for signs of compromise first
Citrix's bulletin publishes no indicators of compromise for this flaw. CISA's KEV catalog entry tells agencies to apply Citrix's fix and points to the forensic triage guidance under Binding Operational Directive 26-04.
Before you upgrade, it's worth saving logs and any crash dumps, because the reports above link the attacks to crashes of the authentication process and to commands hidden in login usernames. If you see either, or unexpected outbound connections from the appliance, bring in incident response before you wipe anything. BleepingComputer also reports that Citrix has supplied Global Deny Lists to block known malicious IP addresses.
Step 4: Upgrade to 14.1-73.41 or 13.1-64.28
Install the fixed build for your branch: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282, or later. If you run several appliances, patch the internet-facing SAML ones first. After the upgrade, confirm the new build number on each one; it is easy to miss a node in a high availability pair.
The federal deadline is October 7
CISA's October 4 alert added the flaw to the catalog based on evidence of active exploitation. The KEV entry sets a due date of October 7, 2026 for US federal civilian agencies and lists ransomware use as "Unknown" as of October 5.
The CISA deadline binds only federal agencies, but three days is a fair signal of how urgent CISA thinks this is. Tenable's FAQ cites the Australian Cyber Security Centre as saying Australian organizations have been affected, so this is not a US-only problem.
Troubleshooting
- You patched to 14.1-73.37 or 13.1-64.23 last week: that fixes CVE-2026-88771, not this flaw. Upgrade again if the appliance uses SAML.
- Your appliance doesn't use SAML: per Citrix it is not affected by CVE-2026-88779. We'd still plan the move to the newer build, since it includes last week's fixes and closes this one if someone enables SAML later.
- The appliance keeps restarting: repeated crashes of the authentication service on a SAML appliance match what admins have reported. Save the evidence, then patch.
- You run FIPS or NDcPP: use 14.1-73.41 FIPS or 13.1-37.282, not the standard builds.
For another flaw that made CISA's list this week, see our guide to the Rejetto HFS vulnerability, and follow the rest on the Cybersecurity tag.
Bottom line
If your NetScaler ADC or Gateway uses SAML as a service provider or identity provider, this NetScaler SAML zero-day applies to you even if you patched last week. Citrix rates it a denial of service, CISA confirms it's exploited, and unconfirmed reports suggest it may allow more. Check your configuration, save logs, and upgrade to 14.1-73.41, 13.1-64.28 or the matching FIPS build, ideally before CISA's October 7 deadline. Watch the Citrix bulletin for any change to the impact rating.
FAQ
Is CVE-2026-88779 being exploited?
Yes. CISA added it to its Known Exploited Vulnerabilities catalog on October 4, 2026, citing evidence of active exploitation, and Citrix has said it observed targeted attacks on unmitigated deployments. How many organizations have been hit has not been disclosed.
Does CVE-2026-88779 allow remote code execution?
Citrix classifies it as a denial of service. An administrator and researcher Kevin Beaumont have described activity that suggests code execution, but as of October 5 that is unconfirmed by Citrix.
I installed 14.1-73.37 last week. Am I safe?
Only if the appliance has no SAML configuration. A SAML service provider or identity provider on 14.1-73.37 or 13.1-64.23 is still vulnerable and needs 14.1-73.41 or 13.1-64.28 or later.
Is there a workaround for the NetScaler SAML flaw?
Citrix's bulletin lists none; the fix is the updated build. By the bulletin's own conditions, an appliance without a SAML configuration is not affected, but removing SAML changes how your users sign in, so it is rarely a quick stopgap.