Citrix NetScaler Updates Fix CVE-2026-88779
Quick Answer
Citrix published CTX697174 for CVE-2026-88779, a high-severity memory-overflow flaw that can cause denial of service in affected customer-managed NetScaler ADC or Gateway appliances configured as a SAML service provider or identity provider. Inventory those configurations and install the supported fixed build for the deployed release stream.
Confirm SAML Exposure And Install The Supported Build
What to do now: Identify customer-managed NetScaler ADC and Gateway appliances, verify whether each is configured as a SAML service provider or identity provider, install the supported fixed build for its exact release stream, validate authentication and high-availability behavior, and preserve evidence.
Last verified: 2026-10-04 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Customer-managed NetScaler ADC and NetScaler Gateway configured as a SAML service provider or SAML identity provider |
|---|---|
| Advisory | CTX697174 / CVE-2026-88779 |
| CVE | CVE-2026-88779 |
| Authoritative release date | 2026-10-03 (PST; initial publication per the Citrix changelog; exact publication time not provided) |
| Authority revision date | 2026-10-04 14:48:46 UTC (CVE record revision added CISA ADP SSVC context and the Citrix technical-blog reference) |
| Affected versions | NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28; NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix. |
| Fixed version | NetScaler ADC and Gateway 14.1-73.41 / 13.1-64.28; NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS; NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282, or later supported releases |
| CVSS base score | 8.7 (official CVSS v4.0) |
| CVSS severity | High |
| Exploitation status | CISA ADP SSVC recorded Exploitation: none at 2026-10-04 14:37:26 UTC; Citrix does not state that exploitation has been observed; no exploitation claim is inferred. |
What Changed
Citrix fixed a memory-overflow condition that can cause denial of service when an affected customer-managed appliance is configured as a SAML service provider or SAML identity provider. The post-cutoff CVE record revision added CISA ADP SSVC context recording exploitation as none and linked Citrix's supporting technical blog; it did not expand Citrix's affected-version or fixed-version statements.
What To Validate Now
- Inventory. Locate customer-managed NetScaler ADC and NetScaler Gateway appliances, record the exact build and platform variant, identify SAML authentication dependencies, owners, internet exposure, clusters, and high-availability peers.
- Establish applicability. Inspect the configuration for SAML service-provider actions (
add authentication samlAction) or SAML identity-provider profiles (add authentication samlIdPProfile), then compare the exact build with Citrix's affected-version table. Do not treat every NetScaler deployment as affected. - Remediate. Upgrade through Citrix's supported channel to 14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, or 13.1-37.282 FIPS/NDcPP or later, according to the installed stream. Citrix-managed cloud services are updated by Citrix.
- Validate. Confirm every node reports the intended fixed build, exercise representative SAML SP or IdP authentication flows, verify cluster and high-availability state, monitor availability and authentication errors, and retain before-and-after configuration and version evidence.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Stage the update against SAML identity-provider metadata, certificates, policies, load balancing, and failover behavior. Preserve configuration backups, audit logs, crash data, and change records before remediation. CISA ADP's `none` value is recorded authority context, not proof that an individual deployment was or was not attacked.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

