DEV Community

threataft
threataft

Posted on Originally published at threataft.com

CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV

A memory overflow in Citrix NetScaler's SAML handler is being actively exploited as a zero-day. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026.

CVE-2026-88779 (CVSS 4.0: 8.7) — Unauthenticated memory overflow (CWE-119) triggered by malicious SAML requests. Crashes the appliance's authentication service, denying VPN and SSO access to the entire organization. Citrix confirms DoS; Norway's NSM initially reported potential RCE — scope remains contested.

If either returns results and you're below the fix versions, patch now.

Fixed in:

  • 14.1-73.41 (14.1 track)
  • 13.1-64.28 (13.1 track)
  • 14.1-73.41 FIPS / 13.1-37.282 (FIPS/NDcPP)

Kevin Beaumont observed exploitation on honeypots running fully patched versions — the exploit may bypass the previous patch batch.

Immediate actions:

  • Patch to fixed version
  • Apply Citrix Global Deny List signatures as interim mitigation
  • Check for appliance crashes during the zero-day window
  • Run compromise assessment on any internet-exposed SAML-enabled appliance

Full analysis: https://threataft.com/articles/netscaler-saml-memory-overflow-cve-2026-88779

Top comments (0)