type: cve · created: 2026-10-05 · updated: 2026-10-05 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
Citrix released emergency updates on 4 October for CVE-2026-88779, a memory-buffer vulnerability (CVSS 8.7) in NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication — either as a SAML service provider (add authentication samlAction) or identity provider (add authentication samlIdPProfile).
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-88779 |
| CVSS | 8.7 (CVSS 4.0) |
| Vendor / product | Citrix / NetScaler ADC and NetScaler Gateway |
| Reported | 2026-10-05 |