CISA has added CVE-2026-88779, a NetScaler flaw that Citrix describes as a memory overflow leading to denial of service, to its Known Exploited Vulnerabilities catalog. The National Vulnerability Database record shows the listing date as Oct. 4 and a federal due date of Oct. 7.
Citrix’s security bulletin, CTX697174, rates the flaw High at CVSS 8.7. It says NetScaler ADC and NetScaler Gateway are affected only when the appliance is configured as a SAML service provider or a SAML identity provider. The affected builds are 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, 14.1-FIPS before 14.1-73.41 FIPS, and 13.1-FIPS and NDcPP before 13.1-37.282. Secure Private Access Hybrid deployments that use NetScaler instances are also affected. Cloud Software Group, which owns Citrix, says it upgrades Citrix-managed cloud services and Adaptive Authentication itself, and it thanks Bishop Fox and watchTowr for working with it on the issue.
The bulletin urges customers to install the fixed builds as soon as possible. It also says how to test whether an appliance meets the precondition: search the NetScaler configuration for an entry that begins with “add authentication samlAction” or “add authentication samlIdPProfile”. An appliance with neither entry does not meet the condition the bulletin describes.
CVE-2026-88779 is a separate flaw from the two Citrix disclosed last week and CyberTech covered in Reports Trace NetScaler Attack Activity to Aug. 21, Five Weeks Before the Advisory. A denial-of-service rating can lull a team into a slower queue, and a KEV listing is the signal that the queue assumption is wrong.
Our read: teams that already reviewed the earlier two flaws should check the SAML configuration first, because it decides whether this one applies to them at all. Teams that find a match should patch ahead of the regular cycle and use the log-retention questions raised in Citrix Patched the Bug Weeks After It Was Exploited to decide how far back to look.
Source: Citrix security bulletin CTX697174 for CVE-2026-88779