Citrix NetScaler Updates Fix CVE-2026-88779

P1 — VALIDATE AND UPDATEHigh · 8.7 (official CVSS v4.0)EXPLOITATION: CISA ADP — NONE

Quick Answer

Citrix published CTX697174 for CVE-2026-88779, a high-severity memory-overflow flaw that can cause denial of service in affected customer-managed NetScaler ADC or Gateway appliances configured as a SAML service provider or identity provider. Inventory those configurations and install the supported fixed build for the deployed release stream.

Confirm SAML Exposure And Install The Supported Build

What to do now: Identify customer-managed NetScaler ADC and Gateway appliances, verify whether each is configured as a SAML service provider or identity provider, install the supported fixed build for its exact release stream, validate authentication and high-availability behavior, and preserve evidence.

Open the authoritative advisory

Last verified: 2026-10-04 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeCustomer-managed NetScaler ADC and NetScaler Gateway configured as a SAML service provider or SAML identity provider
AdvisoryCTX697174 / CVE-2026-88779
CVECVE-2026-88779
Authoritative release date2026-10-03 (PST; initial publication per the Citrix changelog; exact publication time not provided)
Authority revision date2026-10-04 14:48:46 UTC (CVE record revision added CISA ADP SSVC context and the Citrix technical-blog reference)
Affected versionsNetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28; NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix.
Fixed versionNetScaler ADC and Gateway 14.1-73.41 / 13.1-64.28; NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS; NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282, or later supported releases
CVSS base score8.7 (official CVSS v4.0)
CVSS severityHigh
Exploitation statusCISA ADP SSVC recorded Exploitation: none at 2026-10-04 14:37:26 UTC; Citrix does not state that exploitation has been observed; no exploitation claim is inferred.

What Changed

Citrix fixed a memory-overflow condition that can cause denial of service when an affected customer-managed appliance is configured as a SAML service provider or SAML identity provider. The post-cutoff CVE record revision added CISA ADP SSVC context recording exploitation as none and linked Citrix's supporting technical blog; it did not expand Citrix's affected-version or fixed-version statements.

What To Validate Now

  1. Inventory. Locate customer-managed NetScaler ADC and NetScaler Gateway appliances, record the exact build and platform variant, identify SAML authentication dependencies, owners, internet exposure, clusters, and high-availability peers.
  2. Establish applicability. Inspect the configuration for SAML service-provider actions (add authentication samlAction) or SAML identity-provider profiles (add authentication samlIdPProfile), then compare the exact build with Citrix's affected-version table. Do not treat every NetScaler deployment as affected.
  3. Remediate. Upgrade through Citrix's supported channel to 14.1-73.41 or later, 13.1-64.28 or later, 14.1-73.41 FIPS or later, or 13.1-37.282 FIPS/NDcPP or later, according to the installed stream. Citrix-managed cloud services are updated by Citrix.
  4. Validate. Confirm every node reports the intended fixed build, exercise representative SAML SP or IdP authentication flows, verify cluster and high-availability state, monitor availability and authentication errors, and retain before-and-after configuration and version evidence.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Stage the update against SAML identity-provider metadata, certificates, policies, load balancing, and failover behavior. Preserve configuration backups, audit logs, crash data, and change records before remediation. CISA ADP's `none` value is recorded authority context, not proof that an individual deployment was or was not attacked.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.