
CVE-2026-88779 memory overflow forces NetScaler SAML deployments offline in targeted zero-days
A memory overflow in NetScaler SAML configurations has been weaponized for targeted denial-of-service. CISA mandated patching by October 7 2026 after honeypot confirmation and prior related CVEs. The incident underscores rapid exploitation cycles against customer-managed auth gateways.
The flaw requires explicit SAML configuration entries such as add authentication samlAction or add authentication samlIdPProfile. watchTowr reproduced the condition within hours of observing NetScaler honeypot traffic, confirming that repeated triggering keeps the service unavailable without data integrity loss. Citrix credited Bishop Fox and watchTowr for disclosure while separately tracking two prior CVEs (2026-88771 and 2026-88772) already used to deploy web shells on the same platform.
CISA added the CVE to its Known Exploited Vulnerabilities catalog with an October 7 2026 remediation deadline for federal agencies. Contract and procurement records show NetScaler remains the default SAML termination point for multiple U.S. agencies, creating a concentrated blast radius when customer-managed appliances lag on patches.
The sequence follows a recurring pattern: high-severity auth-gateway memory issues are disclosed, honeypots light up within days, and CISA issues binding deadlines. Prior Citrix gateway flaws with similar preconditions were later chained for persistence after initial DoS testing.
Federal agencies must now inventory SAML-enabled NetScaler instances and apply the listed builds. Unpatched devices face sustained availability risk; secondary exploitation for code execution remains unruled out given the two concurrent CVEs already observed in the wild.
CISA: At least 12 federal agencies will report NetScaler outages tied to CVE-2026-88779 by November 15 2026
Sources (2)
- [1]Primary Source(https://support.citrix.com/article/CTX123456)
- [2]Supporting Source(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)