Citrix released emergency updates on 4 October for CVE-2026-88779, a memory-buffer vulnerability (CVSS 8.7) in NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication — either as a SAML service provider (add authentication samlAction) or identity provider (add authentication samlIdPProfile). The flaw is fixed in 14.1-73.41 and 13.1-64.28 (FIPS builds 14.1-73.41 FIPS and 13.1-37.282), with Citrix confirming it has observed targeted attacks against unmitigated deployments causing denial-of-service conditions, including appliances unexpectedly rebooting since Thursday 1 October. Researchers — including Kevin Beaumont, whose patched honeypots crashed and in one case ran a downloaded payload — and watchTowr Labs, which reproduced the flaw, are investigating whether the denial-of-service characterisation masks remote code execution. CISA added CVE-2026-88779 to the KEV catalogue on 4 October, giving US federal agencies until 7 October to mitigate. Organisations that recently upgraded for CVE-2026-88771 through 88778 must re-patch if they use SAML — the flaw sits in the same appliance estate.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-05 |
| Source | BleepingComputer |
| Reliability | Tier 2 |
| CVEs | CVE-2026-88771, CVE-2026-88779 |