Emergency Security Bulletin: Memory Overflow Vulnerability Leading to Denial of Service in Citrix NetScaler ADC and NetScaler Gateway SAML Configurations

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-88779 is a high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML service provider or SAML identity provider.

An unauthenticated remote attacker can trigger the vulnerability to cause a denial of service. If triggered repeatedly, the affected service may remain unavailable.

CVE-2026-88779 is confirmed to be actively exploited and has been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Citrix has released fixed versions for affected NetScaler deployments.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Memory Overflow Vulnerability Leading to Denial of Service in Citrix NetScaler ADC and NetScaler Gateway SAML Configurations

Identifier
CVE-2026-88779
 
PoC or Exploitation
Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
 
CVSS Score
8.7 (High, CVSS v4.0)

Update / Patch:

Citrix has released fixed versions addressing this vulnerability.
 
Affected versions include:
NetScaler ADC and NetScaler Gateway 14.1, before 14.1-73.41
NetScaler ADC and NetScaler Gateway 13.1, before 13.1-64.28
NetScaler ADC FIPS, before 14.1-73.41 FIPS
NetScaler ADC FIPS and NDcPP, before 13.1-37.282
 
Fixed versions include:
NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
NetScaler ADC 14.1-FIPS: 14.1-73.41 FIPS and later releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.282 and later releases
 
Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must upgrade those instances.
 
Citrix Security Bulletin CTX697174:

Description:

CVE-2026-88779 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that leads to denial of service.
 
The vulnerability applies only when the appliance is configured as a SAML service provider or a SAML identity provider. An attacker can trigger it remotely without authentication. If the condition is triggered repeatedly, the service may remain unavailable.

Mitigation Recommendation:

Upgrade to the applicable fixed version for your NetScaler ADC or NetScaler Gateway deployment as soon as possible.
 
Check each appliance for the samlAction and samlIdPProfile configuration entries. Prioritize any appliance that contains either entry.
 
Identify any Secure Private Access Hybrid deployments that use NetScaler instances. Upgrade those instances to the recommended builds.