Citrix warns of CVE-2026-88779, a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. Attackers are already actively exploiting the vulnerability to cause a denial of service. Only environments using SAML authentication are at risk.
The vulnerability falls under CWE-119 and has a CVSS v4.0 score of 8.7. Citrix has observed targeted attacks on NetScaler environments without mitigation. If the vulnerability is triggered repeatedly, the service may remain unavailable. Data appears to be secure. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data,” Citrix reports.
The vulnerability affects only customer-managed installations. Citrix updates its own cloud services, including Gateway Service and Adaptive Authentication, itself.
SAML as a prerequisite
Not every installation is vulnerable. This applies to NetScaler environments running as a Gateway or AAA virtual server and using SAML authentication. Administrators can verify this in the configuration. The line “add authentication samlAction” indicates a role as a SAML SP, while “add authentication samlIdPProfile” indicates a role as a SAML IdP.
Vulnerable versions include NetScaler ADC and Gateway 14.1 prior to 14.1-73.41 and 13.1 prior to 13.1-64.28. FIPS versions prior to 14.1-73.41 FIPS and FIPS/NDcPP versions prior to 13.1-37.282 are also at risk.
Temporary mitigation via the global deny list
Can’t update immediately? Signatures via the Global Deny List offer a solution. This requires the NetScaler Console with “Virtual patching” enabled, plus a version between 14.1-73.37 and 14.1-73.41 or between 13.1-64.23 and 13.1-64.28. The signature version must be at least v24. However, Citrix still recommends upgrading.
Anyone who has recently applied patches for CVE-2026-88771 through CVE-2026-88778 and meets the SAML requirements must update again. In addition, Citrix recommends blocking suspicious IP addresses using NetScaler’s blocklist feature and firewall rules.