A memory overflow in Citrix NetScaler's SAML handler is being actively exploited as a zero-day. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026.
CVE-2026-88779 (CVSS 4.0: 8.7) — Unauthenticated memory overflow (CWE-119) triggered by malicious SAML requests. Crashes the appliance's authentication service, denying VPN and SSO access to the entire organization. Citrix confirms DoS; Norway's NSM initially reported potential RCE — scope remains contested.
If either returns results and you're below the fix versions, patch now.
Fixed in:
- 14.1-73.41 (14.1 track)
- 13.1-64.28 (13.1 track)
- 14.1-73.41 FIPS / 13.1-37.282 (FIPS/NDcPP)
Kevin Beaumont observed exploitation on honeypots running fully patched versions — the exploit may bypass the previous patch batch.
Immediate actions:
- Patch to fixed version
- Apply Citrix Global Deny List signatures as interim mitigation
- Check for appliance crashes during the zero-day window
- Run compromise assessment on any internet-exposed SAML-enabled appliance
Full analysis: https://threataft.com/articles/netscaler-saml-memory-overflow-cve-2026-88779
Top comments (0)