At a glance:
-
Citrix disclosed CVE-2026-88779 after observing active exploitation against NetScaler deployments.
-
Exposure is limited to NetScaler deployments configured for Security Assertion Markup Language (SAML) authentication, making it more narrowly scoped than the recently exploited NetScaler zero-days.
-
Citrix released patches on October 3, 2026, and affected SAML-enabled deployments require the newest updates even if the September 27 NetScaler patches were already applied.
Threat summary
On October 4, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalogue after Citrix confirmed targeted attacks against unpatched Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway deployments.
Citrix disclosed the vulnerability and released fixed builds on October 3. Reports of repeated appliance crashes had emerged on October 1, before the vulnerability or patches were made public.
The disclosure came less than a week after Citrix patched two actively exploited NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772. While those vulnerabilities affected a broad range of NetScaler deployments, CVE-2026-88779 is more narrowly scoped and only affects appliances configured to use Security Assertion Markup Language (SAML) authentication.
SAML is commonly used to provide single sign-on between an organization's identity provider and applications, remote access portals, or virtual private network services. In these deployments, NetScaler acts as either a SAML service provider that accepts authentication assertions from an identity platform or as a SAML identity provider that authenticates users on behalf of other applications.
NetScaler Application Delivery Controller (ADC) and NetScaler Gateway commonly support remote access, application delivery, and federated authentication services. When SAML is enabled, NetScaler processes authentication requests and responses exchanged between users, applications, and identity providers.
CVE-2026-88779 affects this SAML processing functionality. The flaw is a memory overflow vulnerability that can be triggered by specially crafted SAML authentication traffic, causing the nsaaad authentication service to crash. Repeated exploitation can trigger appliance reboots and prevent users from authenticating to applications and services that depend on the affected deployment.
Citrix assigned the vulnerability a Common Vulnerability Scoring System (CVSS) v4 score of 8.7.
Exposure depends on deployment configuration rather than product version alone. Affected appliances contain either an add authentication samlAction entry, indicating a SAML service provider configuration, or an add authentication samlIdPProfile entry, indicating a SAML identity provider configuration.
Exploitation is remote, requires no authentication, and does not require user interaction. Any threat actor capable of reaching the SAML authentication service can attempt exploitation, making internet-accessible deployments the most exposed.
Researchers reproduced the vulnerability shortly after observing activity targeting NetScaler systems, and confirmed that the impact is denial of service, crafted SAML authentication requests were linked to repeated nsaaad crashes and appliance reboots. Users may be unable to sign in to applications, remote access portals, or virtual private network services that rely on the affected NetScaler deployment for SAML authentication.
Analysis
NetScaler deployments that use SAML for remote access, single sign-on, or externally accessible business applications face the greatest operational risk.
A successful attack can disrupt the authentication path that users rely on to access corporate resources, applications, and virtual private network services. The resulting impact depends on the appliance's role within the environment. A deployment protecting a single application may experience a localized outage, while a shared authentication gateway can affect access across multiple business services.
Although exposure is limited to specific SAML-enabled deployments, the exploitation requirements appear straightforward once a threat actor identifies a reachable target. No credentials are required, no user interaction is needed, and SAML is widely used to integrate enterprise identity platforms with externally accessible applications. This makes identifying vulnerable targets relatively simple for adversaries already scanning for NetScaler systems.
NetScaler appliances continue to attract threat actor attention because they sit at the boundary between external users and internal resources. Recent exploitation of CVE-2026-88771 and CVE-2026-88772 demonstrated how quickly adversaries move to target newly disclosed NetScaler vulnerabilities.
Many organizations were still assessing exposure and deploying fixes for those vulnerabilities when CVE-2026-88779 emerged, increasing the likelihood that vulnerable systems remained online during active exploitation.
For CVE-2026-88779, the verified outcome remains service disruption rather than appliance compromise. Repeated exploitation can keep SAML-dependent authentication services unavailable, preventing employees, administrators, contractors, and customers from accessing applications routed through the affected deployment. The downstream impact is environment-dependent and is primarily driven by which services rely on the affected NetScaler instance.
Organizations that installed the September 27 updates for CVE-2026-88771 through CVE-2026-88778 may still be vulnerable if SAML authentication is enabled and the October 3 updates have not been applied. Repeated crashes or reboots on recently patched appliances may therefore indicate exploitation of this separate vulnerability rather than issues related to the earlier vulnerabilities.
Mitigations
Upgrade affected NetScaler ADC and NetScaler Gateway deployments to version:
Review configurations for add authentication samlAction and add authentication samlIdPProfile entries to identify appliances that meet the vulnerability's exploitation requirements, including systems updated during the September remediation cycle. Prioritize reachable SAML-enabled deployments that support authentication, remote access, or business-critical applications.
Monitor authentication logs, nsaaad crashes, Pitboss restart events, unexpected reboots, and repeated requests targeting SAML authentication services to help identify activity consistent with reported exploitation.