🔴 CVE-2026-88779

CVE-2026-88779 is an unauthenticated, remotely exploitable memory overflow (CWE-119) in NetScaler ADC and NetScaler Gateway that causes a Denial of Service condition. No authentication or user interaction is required, and the vulnerability has been confirmed as actively exploited in the wild targeting SAML gateway configurations. CISA has issued an alert covering this vulnerability as a critical zero-day being weaponised against these internet-facing appliances.

← Back to Overview
HIGH_RISK
Risk Level
8.7
CVSS Score
NETWORK
Attack Vector
Impact
ATT&CK Tactic
T1499 — Endpoint Denial of Service
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-10-04

Added to CISA KEV: 2026-10-04 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-10-04)

Summary

CVE-2026-88779 is a critical memory overflow vulnerability—classified as a buffer overflow (CWE-119)—affecting NetScaler ADC and NetScaler Gateway products. By improperly handling memory buffers, this vulnerability allows a remote, unauthenticated attacker to trigger a crash or render the affected component unresponsive, resulting in a Denial of Service (DoS) condition. It is a significant concern for organizations relying on these appliances to manage network traffic or facilitate secure access, as successful exploitation disrupts services and impacts availability.

Exploitation

  • Active Exploitation: There are reports of this vulnerability being actively exploited in the wild, with attackers specifically targeting SAML gateways to knock them offline [3].
  • Threat Actors/Campaigns: While specific threat actor attribution is not detailed in current disclosures, CISA has included this issue in an alert regarding critical zero-day vulnerabilities being exploited in these products [2].
  • Availability: Public Proof-of-Concept (PoC) or specialized exploit tools are not explicitly documented in the available records, but the active exploitation indicates that functional exploit code is circulating.
  • Prerequisites:
- Network vs Local: This is a remote vulnerability, meaning it can be exploited over the network [4]. - Authentication: No authentication is required to initiate the attack [1]. - User Interaction: No user interaction is required for successful exploitation [1].

Affected Products & Patches

  • Affected Versions: The vulnerability impacts several configurations, including:
- ADC before 14.1-73.41 - ADC before 13.1-64.28 - ADC before 14.1-73.41 FIPS - (Additional versions are covered in the official Citrix security bulletin) [5][6].
  • Patch Availability: Citrix has released security updates to address this issue. Organizations are advised to consult the official Citrix Security Bulletin (CTX697174) for specific upgrade paths and hotfixes [1].
  • Mitigations: There are no widely recognized workarounds other than applying the provided software updates to reach the non-vulnerable versions.

Impact

  • Access/Capability: Successful exploitation results in a Denial of Service, effectively crashing or forcing the NetScaler ADC or Gateway component into an unresponsive state, which halts its function as a traffic controller or authentication gateway.
  • Business Risk: For internet-facing deployments, the business risk is high, as the vulnerability can be leveraged by external attackers to cause widespread service outages, potentially disrupting business continuity, remote access for employees, and the availability of critical applications protected by the appliance.

Sources

  1. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for ...

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779 The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system (s). Cloud Software Group Holdings, Inc. and its af…

  2. Critical Zero-Day Vulnerabilities Exploited in Citrix ...

    CISA is amplifying Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE- ...

  3. Citrix NetScaler CVE-2026-88779 Exploited in the Wild to ...

    Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline https://lnkd.in/eTe2-4Kb.

  4. CVE-2026-88779 - Vulnerability Details - OpenCVE

    The vulnerability is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, leading to a denial of service condition when an attacker can cause the affected components to crash or become unresponsive. The weakness involves improper handling of memory buffers and is categorized as a buffer…

  5. CVE Record: CVE-2026-88779

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and ...