Citrix NetScaler ADC and Gateway SAML Authentication Memory Overflow Vulnerability
Release Date: 4th October 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-88779 is an unauthenticated memory overflow vulnerability (CWE-119) in the SAML authentication handler of Citrix NetScaler ADC and NetScaler Gateway. It is rated CVSS v4.0 8.7. Citrix confirms it can crash the appliance and cause a denial of service, taking VPN and single sign-on access offline.
Citrix disclosed it in security bulletin CTX697174, separate from the earlier bulletin CTX697096 that covers CVE-2026-88771 to CVE-2026-88778 (see CERTVU Advisory 336).
What are the systems affected?
Only appliances with SAML authentication configured are vulnerable, either as a SAML Service Provider ("add authentication samlAction") or a SAML Identity Provider ("add authentication samlIdPProfile"). The following versions are affected:
NetScaler ADC and Gateway 14.1, before 14.1-73.41 – (Affected)
NetScaler ADC and Gateway 13.1, before 13.1-64.28 – (Affected)
NetScaler ADC 14.1-FIPS, before 14.1-73.41 FIPS, and 13.1-FIPS/NDcPP, before 13.1-37.282 – (Affected)
Appliances already updated to 14.1-73.37 or 13.1-64.23/64.24 for the earlier bulletin (CVE-2026-88771 to CVE-2026-88778) are still affected by this flaw. Customer-managed (on-premises) appliances must be updated by the customer, and end-of-life releases receive no fix.
Not affected / patched version:
NetScaler ADC and Gateway 14.1-73.41 or later, and 13.1-64.28 or later – (Not affected)
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS or later, and 13.1-FIPS/NDcPP 13.1-37.282 or later – (Not affected)
What does this mean?
Successful exploitation may allow attackers to:
- Crash NetScaler appliances remotely without credentials, cutting off VPN, SSO and gateway access for users
- Possibly achieve code execution on the appliance, which is disputed but not ruled out by all sources
- Repeatedly disrupt remote access to services that depend on the NetScaler, or use crashes to hide other activity
Mitigation process?
CERTVU recommends the following:
-
Upgrade Immediately
Upgrade to 14.1-73.41 or later, 13.1-64.28 or later, or the fixed FIPS/NDcPP build listed above. This applies even if the appliance was already patched for CVE-2026-88771 and CVE-2026-88772. -
Identify SAML-Enabled Appliances
-
Apply Citrix's Global Deny Lists as a Stopgap
-
Investigate Unexplained Crashes and Compromise
Reference
- https://support.citrix.com/external/article/CTX697174
- https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-88779
- Download advisory (English): Citrix NetScaler ADC and Gateway SAML Authentication Memory Overflow Vulnerability