T
Threats
Citrix NetScaler Critical Vulnerabilities and SAML Denial of Service
Overview
Products: Citrix NetScaler ADC and Citrix NetScaler Gateway, customer-managed deployments.
CVE: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778, CVE-2026-88779, CVE-2026-88774
Severity: Critical
Advisory date: 5 October 2026.
This advisory updates our previous report: Citrix NetScaler ADC and Gateway Multiple Critical Vulnerabilities.
Citrix has now disclosed nine vulnerabilities affecting customer-managed NetScaler ADC and Gateway, including three critical flaws and a separate SAML denial-of-service vulnerability. One of the critical flaws allows unauthenticated command execution across all configurations of affected builds, while exploitation of the other vulnerabilities depends on specific features being enabled.
Citrix confirms observed exploitation of CVE-2026-88771 and CVE-2026-88772. The ASD ACSC update of 30 September reports confirmed exploitation in Australian organisations and recommends reviewing evidence of compromise from at least 4 September 2026. This supersedes the alert’s earlier statement that Australian exploitation had not been confirmed. The CISA alert, revised 2 October also confirms global exploitation and lists both CVEs in its Known Exploited Vulnerabilities catalogue.
Given the confirmed exploitation in Australia and globally, organisations should prioritise patching affected NetScaler instances and reviewing logs and other evidence for signs of compromise.
Affected Versions
Original eight-CVE bulletin: CVE-2026-88771 to CVE-2026-88778
The following are the supported branch ranges and minimum updated builds published in Citrix bulletin CTX697096. Configuration prerequisites for each CVE are listed separately below.
NetScaler ADC and NetScaler Gateway 14.1
Affected: 14.1 before 14.1-73.37.
Fixed: 14.1-73.37 and later 14.1 releases.
NetScaler ADC and NetScaler Gateway 13.1
Affected: 13.1 before 13.1-64.23.
Fixed: 13.1-64.23 and later 13.1 releases.
NetScaler ADC 14.1-FIPS
Affected: 14.1-FIPS before 14.1-73.37 FIPS.
Fixed: 14.1-73.37 FIPS and later 14.1-FIPS releases.
NetScaler ADC 13.1-FIPS and 13.1-NDcPP
Affected: 13.1-FIPS and 13.1-NDcPP before 13.1-37.279.
Fixed: 13.1-37.279 and later releases of the respective branch.
CVE-2026-88774 version nuance: Citrix supplementary guidance says this issue was already addressed in all builds since 14.1-72.X, without naming an exact first build. The controlling security bulletin still publishes the aggregated thresholds above. Do not use the earlier 14.1-72.X fix as a remediation target for the other CVEs.
Separate SAML vulnerability: CVE-2026-88779
The following ranges apply when SAML SP or SAML IdP configuration is present, as specified in Citrix bulletin CTX697174.
NetScaler ADC and NetScaler Gateway 14.1
Affected: 14.1 before 14.1-73.41.
Fixed: 14.1-73.41 and later 14.1 releases.
Not affected: Deployments that do not meet the SAML SP or SAML IdP prerequisite are outside this CVE's stated configuration scope. This does not exclude exposure to the original eight CVEs.
Source: Citrix CTX697174 affected versions and SAML prerequisites
NetScaler ADC and NetScaler Gateway 13.1
Affected: 13.1 before 13.1-64.28.
Fixed: 13.1-64.28 and later 13.1 releases.
Not affected: Deployments that do not meet the SAML SP or SAML IdP prerequisite are outside this CVE's stated configuration scope. This does not exclude exposure to the original eight CVEs.
Source: Citrix CTX697174 affected versions and SAML prerequisites
NetScaler ADC 14.1-FIPS
Affected: 14.1-FIPS before 14.1-73.41 FIPS.
Fixed: 14.1-73.41 FIPS and later 14.1-FIPS releases.
Not affected: Deployments that do not meet the SAML SP or SAML IdP prerequisite are outside this CVE's stated configuration scope. This does not exclude exposure to the original eight CVEs.
Source: Citrix CTX697174 affected versions and SAML prerequisites
NetScaler ADC 13.1-FIPS and 13.1-NDcPP
Affected: 13.1-FIPS and 13.1-NDcPP before 13.1-37.282.
Fixed: 13.1-37.282 and later releases of the respective branch.
Not affected: Deployments that do not meet the SAML SP or SAML IdP prerequisite are outside this CVE's stated configuration scope. This does not exclude exposure to the original eight CVEs.
Source: Citrix CTX697174 affected versions and SAML prerequisites
Vulnerability Breakdown
CVE-2026-88771 - Unauthenticated remote command execution
Severity: Critical.
CVSS: 9.5, version 4.0.
Description: Improper input validation allows an unauthenticated remote attacker to execute arbitrary commands.
Impact: Remote code execution and appliance compromise.
Conditions: All NetScaler ADC and Gateway configurations, including the default configuration. No additional feature is required.
CVE-2026-88772 - DTLS memory overflow
Severity: Critical.
CVSS: 9.5, version 4.0.
Description: A memory overflow can enable remote code execution or denial of service.
Impact: Appliance compromise or service disruption.
Conditions: DTLS must be enabled. It is enabled by default on VPN virtual servers unless explicitly disabled.
CVE-2026-88773 - HTTP request smuggling
Severity: Critical.
CVSS: 9.3, version 4.0.
Description: Inconsistent interpretation of HTTP requests permits HTTP request smuggling.
Impact: Integrity impacts on the appliance and downstream systems, as reflected in the vendor CVSS vector.
Conditions: HTTP configuration must be enabled, including LB, CS, VPN or Authentication virtual servers of type HTTP or SSL.
CVE-2026-88775 - Gateway or AAA memory overflow
Severity: High.
CVSS: 8.8, version 4.0.
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption, with limited confidentiality and integrity impacts in the vendor CVSS vector.
Conditions: Configured as a Gateway for SSL VPN, ICA Proxy, CVPN or RDP Proxy, or as an AAA virtual server.
CVE-2026-88776 - Oracle load-balancing memory overflow
Severity: High.
CVSS: 8.8, version 4.0.
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption, with limited confidentiality and integrity impacts in the vendor CVSS vector.
Conditions: An Oracle-type load-balancing virtual server must be configured.
CVE-2026-88777 - Non-HTTP Layer 7 memory overflow
Severity: High.
CVSS: 8.8, version 4.0.
Description: A memory overflow can cause unpredictable or erroneous behaviour or denial of service.
Impact: Service disruption, with limited confidentiality and integrity impacts in the vendor CVSS vector.
Conditions: Configured as LB/CS or CGNAT-LSN/NAT64 with a non-HTTP Layer 7 protocol feature enabled. Review the vendor checks for FTP, RTSP, DNS64 and NAT64.
CVE-2026-88778 - TCP initial sequence number prediction
Severity: High.
CVSS: 8.8, version 4.0.
Description: TCP initial sequence numbers can be predicted under the documented configuration conditions.
Impact: Confidentiality, integrity and availability impacts described by the vendor CVSS vector.
Conditions: A vendor-listed TCP-capable virtual server must be present and Enhanced ISN Generation must be disabled.
Action: Apply the vendor-required Enhanced ISN Generation configuration change as well as the relevant upgrade. See Enhanced ISN Generation guidance.
CVE-2026-88779 - SAML memory overflow and denial of service
Severity: High.
CVSS: 8.7, version 4.0.
Description: A memory overflow can cause denial of service. This is the separately disclosed SAML issue.
Impact: Loss of service availability. The current vendor bulletin describes denial of service, not remote code execution.
Conditions: Configured as a SAML service provider or SAML identity provider. Check for add authentication samlAction or add authentication samlIdPProfile entries.
CVE-2026-88774 - HTTP URL-based feature policy bypass
Severity: High.
CVSS: 7.0, version 4.0.
Description: Improper use of HTTP URL-based expressions permits feature policy bypass.
Impact: Bypass of security policies, including WAF rules in the vendor supplementary guidance.
Conditions: A policy expression using HTTP URL-based expressions must be configured.
Mitigation
Upgrade urgently: For SAML deployments, use at least 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 for FIPS/NDcPP, or later releases in the appropriate branch. These exceed the original eight-CVE minimum build thresholds. Confirm the relevant platform and review CTX697174 updated builds and CTX697096 requirements.
Apply the TCP configuration change: For CVE-2026-88778 exposure, enable Enhanced ISN Generation using the vendor's TCP settings guidance. A software upgrade alone is not the complete prescribed action. See NetScaler Enhanced ISN Generation configuration.
Review all prerequisites: Check DTLS, HTTP/SSL virtual servers, HTTP URL-based policy expressions, Gateway/AAA, Oracle load balancing, non-HTTP Layer 7 features, TCP settings and SAML SP/IdP configuration against the two security bulletins.
Assess compromise: Review device and external logs from at least 4 September 2026, as recommended by ASD ACSC. Use NetScaler Console IoC detection where supported, or contact Citrix support. A clean IoC scan does not prove that compromise has not occurred.
Preserve evidence before recovery: If compromise is suspected, preserve relevant evidence before patching or rebuilding where possible. Follow CISA evidence-preservation advice and Citrix incident response steps. Isolate the appliance, revoke or rotate exposed credentials and certificates, investigate connected systems, and rebuild from trusted software and a pre-compromise configuration. Patching does not remove compromise artifacts.
Plan upgrade operations: Citrix supplementary guidance warns that 13.1-64.23 can cause cyclic reboot during upgrade when variables are configured; it recommends 13.1-64.24 for that operational issue. Do not stop at either build for SAML exposure, which requires 13.1-64.28 or later. The same guidance says SAML assertions must be signed and validated following the security update; confirm that the IdP issues signed assertions.
Monitor after remediation: Forward appliance logs to an external logging or SIEM platform and follow Citrix recovery and hardening guidance. Contact Citrix support and report Australian incidents through ASD ACSC assistance channels.
Summary for IT Teams
Products: Customer-managed Citrix NetScaler ADC and Gateway, including relevant FIPS/NDcPP and Secure Private Access Hybrid instances.
Threat Level: Critical, highest CVSS v4.0 9.5. Exploitation is confirmed for CVE-2026-88771 and CVE-2026-88772.
Action Required: Apply the correct branch updates, use the newer SAML fixed builds where applicable, enable Enhanced ISN Generation for CVE-2026-88778 exposure, and assess for compromise. Preserve evidence and invoke incident response if compromise is suspected.
Reference
Citrix security bulletin CTX697096: eight NetScaler vulnerabilities
Citrix supplementary guidance, upgrade caveats and compromise assessment
Citrix earlier SAML deployment guidance, updated 2 October 2026
NetScaler document history: security build replacement notices
Need Help?
If your organisation needs assistance assessing exposure, planning remediation or investigating potential compromise, the Secure ISS SOC team is ready to help. Call 1300 769 460 or email the Secure ISS SOC team. See Secure ISS contact details.

