Skip to main content
All posts
Latest ADC Portal

High zero-day in Citrix NetScaler ADC & Gateway: Patch CVE-2026-88779

A high-severity memory overflow vulnerability was disclosed, affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

High zero-day in Citrix NetScaler ADC & Gateway: Patch CVE-2026-88779
5 hours ago Updated 4 min read
⚠️
Tracked as CVE-2026-88779, this CVE follows closely on the heels of CVE-2026-88771 and CVE-2026-88772.

A memory overflow vulnerability was disclosed over the weekend, affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

Tracked as CVE-2026-88779, this security flaw carries a CVSS v4.0 score of 8.7 and can be exploited remotely by an unauthenticated attacker to cause a complete Denial of Service (DoS) on vulnerable appliances.

Cloud Software Group has released security updates to mitigate this vulnerability. Security engineers and system administrators are strongly urged to review their SAML configurations and apply the necessary patches immediately.

NetScaler vulnerability overview and threat details

CVE-2026-88779 stems from an Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119). Specifically, a memory overflow issue within the appliance's SAML processing logic allows remote attackers to trigger a system crash or process exhaustion, rendering application delivery controller (ADC) functions and gateway access unavailable.

Vulnerability summary:

  • CVE ID: CVE-2026-88779
  • Severity rating: High
  • CVSS v4.0 vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N (Base Score: 8.7)
  • Common weakness enumeration: CWE-119 (Memory Buffer Overflow)
  • Impact: Unauthenticated Denial of Service (High Availability Impact)
  • Discovered/acknowledged by: Bishop Fox and watchTowr

Affected Citrix NetScaler appliances and preconditions

The vulnerability affects customer-managed instances of Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway), including Secure Private Access Hybrid deployments utilizing NetScaler instances.

💡
Note on Cloud Services: This advisory applies exclusively to customer-managed appliances. Cloud Software Group manages updates directly for Citrix-managed cloud services and Adaptive Authentication.

Preconditions for exploitation

For an appliance to be vulnerable to CVE-2026-88779, it must be explicitly configured as either a SAML Service Provider (SP) or a SAML Identity Provider (IdP).

How to check if your Citrix NetScaler appliance meets the vulnerability preconditions

Security engineers can inspect their NetScaler configuration files (ns.conf) or run CLI queries to determine if SAML functionality is enabled:

1. Configured as a SAML Service Provider (SP)

Search for configuration entries matching:

add authentication samlAction

2. Configured as a SAML Identity Provider (IdP)

Search for configuration entries matching:

add authentication samlIdPProfile
🚧
If either entry is present and your appliance runs a version older than the applicable fixed build, it requires remediation.

Affected versions and fixed releases

The following supported versions of NetScaler ADC and Gateway are vulnerable. You must upgrade to the corresponding fixed build (or later):

Affected NetScaler versions Minimum fixed release
NetScaler ADC & Gateway 14.1 14.1-73.41 and later
NetScaler ADC & Gateway 13.1 13.1-64.28 and later
NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later
NetScaler ADC 13.1-FIPS & 13.1-NDcPP 13.1-37.282 (FIPS/NDcPP) and later

Action required: How to fix

To remediate CVE-2026-88779, security engineers should do the following:

1. Log into the ADC Portal

The Loadbalancer.org ADC Portal automatically scans for Common Vulnerabilities and Exposures (CVEs) affecting connected Application Delivery Controllers (ADCs) by querying the NIST National Vulnerability Database.

Once logged in to your ADC Portal account, navigate to Security > Insights.

From there, identify your affected NetScaler appliances.

2. Log into your NetScaler appliance

Run the CLI commands or inspect ns.conf on all deployed NetScaler nodes to verify if SAML SP (add authentication samlAction) or SAML IdP (add authentication samlIdPProfile) profiles are active.

3. Preserve logs and state evidence

Because updating software can overwrite volatile forensic traces, check for signs of potential compromise first if you manage internet-facing instances. Take snapshot logs and evaluate system activity before applying the patch.

4. Apply the official firmware patches via the ADC Portal

Upgrade affected hardware, virtual appliances (VPX), and FIPS-compliant devices to the respective patched version (e.g., 14.1-73.41 or 13.1-64.28).

Deploy the fixed software build across all customer-managed devices immediately by clicking 'Update ADC':

🚧
Make sure any NetScaler instances backing Secure Private Access Hybrid environments are also upgraded in parallel.

5. Run HA node updates

Update high-availability (HA) pairs sequentially (secondary node first, failover, then former primary node) to maintain uninterrupted service availability during patching.

6. Contact our support team for a free load balancer health check

The ADC Portal can help you identify, mitigate, and resolve Common Vulnerabilities and Exposures (CVEs) across your NetScaler, F5, Progress Kemp and Loadbalancer.org fleet. To find out how, contact our support team.

Further reading

Improve your security posture with the ADC Portal.

Learn more

Related posts