NetScaler SAML CVE-2026-88779 hits KEV: patch by October 7
CISA added Citrix NetScaler SAML flaw CVE-2026-88779 to KEV with a three-day deadline. Citrix says DoS. Researchers report a honeypot running malware.
CISA added CVE-2026-88779, a Citrix NetScaler SAML vulnerability, to its Known Exploited Vulnerabilities catalog on October 4 and gave federal agencies until October 7 to deal with it. Three days. If your NetScaler ADC or Gateway handles single sign-on for your team, this is the patch you do before coffee on Monday. And once again, the vendor's "denial of service" label is underselling it.
What actually happened
Citrix bulletin CTX697174, published October 3, describes CVE-2026-88779 as a memory overflow that leads to denial of service, rated CVSS v4.0 8.7. It only applies when the appliance is configured as a SAML Service Provider (add authentication samlAction) or SAML Identity Provider (add authentication samlIdPProfile). Citrix credits Bishop Fox and watchTowr for the disclosure.
Fixed builds:
- 14.1-73.41 and later
- 13.1-64.28 and later
- 14.1-73.41 FIPS and later
- 13.1-37.282 and later (FIPS and NDcPP)
Citrix-managed cloud services are patched by Cloud Software Group. Everything you host yourself is on you.
CISA's KEV entry goes further than a normal listing: apply mitigations, do forensic triage, and stop using the product if you can't fix it.
Now the label problem. BleepingComputer reports that researcher Kevin Beaumont saw evidence of code execution, including a honeypot that was running a downloaded malware binary. watchTowr says it reproduced the bug but hasn't published details. We treat that RCE claim as credible but unconfirmed. It makes no difference to the plan: patch now.
This is NetScaler's second emergency cycle in about a week. CISA warned on September 27 about other zero-days being exploited in the same appliances.
Why a SAML NetScaler bug matters for your business
SAML on a NetScaler means the box brokers logins: to your VPN, your Microsoft 365, your line-of-business apps. Whoever controls the identity broker controls who gets in. That makes it the worst possible place to triage by the vendor's impact class.
We made this point in August with CVE-2026-8452. Same appliance family, same "DoS" wording, same researchers walking it toward code execution. Treat a NetScaler memory bug as RCE until someone proves it isn't.
Today's list:
- Run
show versionand compare against the fixed builds above. - Grep your config for
samlActionandsamlIdPProfile. If either exists, you're exposed. Patch first, investigate second. - If you were exposed and unpatched, assume someone got in. Look for unknown binaries and processes, then rotate SAML signing certificates, session secrets, and directory service accounts.
- Write down who owns this box. If it came with an MSP contract, ask them for the patch time in writing.
Key takeaways
- CVE-2026-88779 (CVSS 8.7) affects NetScaler ADC and Gateway configured as a SAML SP or IdP
- CISA added it to KEV on October 4 with an October 7 federal deadline and required forensic triage
- Fixed in 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 and later
- Citrix calls it denial of service; researchers report signs of code execution, including malware on a honeypot
- A patch doesn't remove an attacker who is already in, so rotate SAML certificates and service credentials if you were exposed
Your login broker shouldn't be an orphan. We map every internet-facing appliance a client runs, check it against KEV, and assign a named owner and a patch window before the deadline hits. See what we operate, or tell us what's sitting in front of your SSO.
Sources: Citrix CTX697174, CISA KEV catalog, BleepingComputer, CISA alert, September 27.
- #citrix
- #netscaler
- #cve
- #cisa-kev
- #saml
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Zammad CVE-2026-102489 on CISA KEV: patch your helpdesk
CISA added two exploited Zammad flaws to KEV. Chained, they turn a hijacked session into root on your helpdesk server. Upgrade to Zammad 7.2.0 and check for compromise.
Read itSC WordPress backdoor rebuilds itself: cleanup order matters
Sucuri found the SC WordPress backdoor hiding in 8 files, the database and shared memory. Delete in the wrong order and it rewrites itself in seconds.
Read it