(TLP:CLEAR) Vulnerability Notification – Citrix NetScaler SAML Zero-Day Actively Exploited
Created: Monday, October 5, 2026 - 15:41
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using customer-managed Citrix NetScaler ADC or NetScaler Gateway appliances configured as a SAML service provider (SP) or SAML identity provider (IdP), including Secure Private Access Hybrid deployments that rely on NetScaler instances. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: A high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway is being actively exploited in the wild as a zero-day. Tracked as CVE-2026-88779 (CVSS v4.0 8.7), the vulnerability impacts appliances configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP). Successful exploitation could allow a remote attacker to cause a denial of service, and Citrix notes that the service may remain unavailable if the condition is triggered repeatedly.
This vulnerability is separate from CVE-2026-88771 and CVE-2026-88772, which WaterISAC notified members of on September 28 and October 2. The fixed versions listed in those notifications do not address CVE-2026-88779. Members who upgraded their NetScaler appliances last week are encouraged to upgrade again to the versions listed below.
NetScaler appliances sit at the network edge and often provide VPN, remote access, and authentication services for staff, contractors, and critical support systems. A denial of service could disrupt that access.
Citrix has released fixed versions for customer-managed appliances, and is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication directly.
Affected Versions:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 – upgrade to 14.1-73.41 or later
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 – upgrade to 13.1-64.28 or later
- NetScaler ADC 14.1-FIPS before 14.1-73.41 FIPS – upgrade to 14.1-73.41 FIPS or later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282 – upgrade to 13.1-37.282 or later
Recommended Actions
WaterISAC strongly encourages members to review Citrix’s advisory and take the following actions:
- Determine whether an appliance is configured as a SAML SP or SAML IdP by checking the NetScaler configuration for entries matching
add authentication samlActionoradd authentication samlIdPProfile. - Upgrade affected appliances to the fixed versions listed above as soon as possible, including appliances that were upgraded last week.
- Follow Citrix’s Steps to Take if NetScaler ADC is Suspected to be Compromised.
Additional Reading
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779
- Understanding and Addressing CVE-2026-88779 in Citrix NetScaler ADC and Citrix NetScaler Gateway
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
WaterISAC PIRs: 8
