CVE- 2026-88779 is a high‑severity memory overflow that affected Citrix NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication. Exploited as a zero‑day before fixes arrived, the flaw could cause a denial of service by triggering unsafe memory handling in the SAML processing path, potentially taking the affected service offline and disrupting VPN, gateway, AAA, or application access.
Citrix attributes a CVSS v4.0 score of 8.7 and notes no established impact on confidentiality or data integrity, though the runtime impact is a service outage. The vulnerability targets NetScaler deployments acting as either a SAML service provider (SP) or an IdP, and requires one of two SAML preconditions: add authentication samlAction or add authentication samlIdPProfile.
Affected products and remediations were published by Citrix. The vulnerable branches include NetScaler ADC/Gateway 14.1 (before 14.1-73.41), 13.1 (before 13.1-64.28), 14.1‑FIPS (before 14.1-73.41 FIPS), and 13.1‑FIPS/NDcPP (before 13.1-37.282), with fixed versions listed accordingly. Public exploitation occurred prior to patches, and CISA added CVE-2026-88779 to the KEV catalogue on 4 October 2026, setting a 7 October remediation deadline for covered federal agencies.
While public PoC code remains unavailable, researchers have observed crashes and reboots on patched devices before the CVE was disclosed, confirming real‑world exploitation. Organisations are advised to upgrade to fixed builds, verify SAML configurations, and hunt for cryptic authentication failures or unstable appliance behaviour.