Citrix NetScaler ADC and Gateway SAML Authentication Memory Overflow Vulnerability

Release Date: 4th October 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-88779 is an unauthenticated memory overflow vulnerability (CWE-119) in the SAML authentication handler of Citrix NetScaler ADC and NetScaler Gateway. It is rated CVSS v4.0 8.7. Citrix confirms it can crash the appliance and cause a denial of service, taking VPN and single sign-on access offline.

Citrix disclosed it in security bulletin CTX697174, separate from the earlier bulletin CTX697096 that covers CVE-2026-88771 to CVE-2026-88778 (see CERTVU Advisory 336).

Reference

  1. https://support.citrix.com/external/article/CTX697174
  2. https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  4. https://nvd.nist.gov/vuln/detail/CVE-2026-88779