Yes, CVE-2026-88779 is reported as exploited, and Citrix says it can cause denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances configured as a SAML service provider (SP) or identity provider (IdP). For customer-managed appliances, check for those SAML settings and compare the installed build with Citrix’s fixed versions. Citrix has not identified remote code execution as the documented impact.
What CVE-2026-88779 does
Citrix describes CVE-2026-88779 as a memory overflow that can lead to denial of service (DoS). Its advisory assigns the vulnerability a CVSS v4.0 base score of 8.7 and classifies it as CWE-119. The DoS rating means an attacker may disrupt service; it does not establish that every vulnerable appliance will crash.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Citrix NetScaler MPX 7500/9500 (8x10/100/1000Base-T Copper Ethernet Ports) with 320GB Hard Disk... | $399.99 | Buy on Amazon |
The vulnerability has a specific configuration precondition: NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP. Citrix’s technical details and remediation guidance are in its CVE-2026-88779 security bulletin.
Is my NetScaler affected?
Check both the appliance’s configuration and its product branch/build. A SAML configuration meets the advisory’s stated precondition; the installed version determines whether the build falls below Citrix’s affected-version threshold. Citrix’s advisory lists the following thresholds and fixed builds:
#1 Best Overall
- Citrix NetScaler MPX 7500/9500 (8x10/100/1000Base-T copper Ethernet ports)
| Product and branch | Affected versions | Fixed build |
|---|---|---|
| NetScaler ADC or Gateway 14.1 | Before 14.1-73.41 | 14.1-73.41 or later |
| NetScaler ADC or Gateway 13.1 | Before 13.1-64.28 | 13.1-64.28 or later |
| NetScaler ADC or Gateway 14.1 FIPS | Before 14.1-73.41 FIPS | 14.1-73.41 FIPS or later |
| NetScaler ADC or Gateway 13.1 FIPS/NDcPP | Before 13.1-37.282 | 13.1-37.282 |
These thresholds are from Citrix’s bulletin, not a substitute for checking the current advisory. Confirm the exact edition and branch against the vendor guidance before upgrading, especially for FIPS or NDcPP deployments.
How to check for the SAML configuration
Citrix says administrators can search the appliance configuration for these command strings:
add authentication samlActionindicates a SAML SP configuration.add authentication samlIdPProfileindicates a SAML IdP configuration.
Use the appropriate configuration-management or appliance inspection process for your environment, and verify the installed build as well. Not finding either string means the advisory’s stated SAML precondition was not found in that check; it is not a general security assessment of the appliance.
Which deployments need to act?
Customer-managed ADC and Gateway
Citrix’s advisory applies to customer-managed NetScaler ADC and Gateway appliances. If the SAML configuration is present and the appliance is on an affected build, upgrade to the applicable fixed build listed above, following Citrix’s instructions for the relevant branch and edition.
Recommended Free Tools
Citrix-managed cloud services
Citrix says Cloud Software Group updates Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Customers using those managed services should follow Citrix’s service communications rather than treating the appliances as customer-managed upgrade targets.
Secure Private Access Hybrid
Secure Private Access Hybrid deployments that use NetScaler instances are included. Administrators must upgrade those NetScaler instances according to the applicable branch and edition guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is CVE-2026-88779 being exploited?
Contemporaneous reporting described zero-day exploitation. NIST’s National Vulnerability Database record says the CVE was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026, and lists October 7, 2026 as its due date. The record lists the action as applying mitigations according to vendor instructions and CISA BOD 26-04 guidance. See the NVD record and check the live catalog and current agency instructions, because due dates and required actions can change.
Reporting also said researchers were investigating possible remote code execution (RCE). That is not the impact documented in Citrix’s advisory: Citrix describes denial of service. Do not treat possible RCE as confirmed based on the cited sources.
How CVE-2026-88779 differs from other NetScaler alerts
This article concerns CVE-2026-88779 specifically. Its defining combination is a memory overflow, a SAML SP/IdP configuration precondition, and a vendor-documented denial-of-service impact. Do not assume that details or fixes from other recently disclosed NetScaler CVEs apply to this vulnerability; use the CVE identifier and the matching Citrix bulletin when checking remediation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

