CVE-2026-88779 is a memory-buffer bounds vulnerability in Citrix NetScaler ADC and NetScaler Gateway configured as a SAML Service Provider or SAML Identity Provider with Gateway or AAA functionality. An unauthenticated remote attacker can trigger denial of service through the affected SAML authentication handling. Observed failures include repeated nsaaad process crashes that cause the Pitboss supervisor to reach its restart limit and reboot the appliance. Affected releases are ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, ADC 14.1 FIPS before 14.1-73.41 FIPS, and ADC 13.1 FIPS and NDcPP before 13.1-37.282. The vulnerability has been actively exploited. Remote code execution through this specific vulnerability remains unconfirmed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
73 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
According to the content, this CVSS 4.0 8.7 memory overflow vulnerability allows unauthenticated remote attackers to crash Citrix NetScaler appliances using malicious SAML requests. Repeated exploitation can cause persistent denial of service, disrupting authentication, VPN, ICA Proxy, and AAA services. Exploitation requires configuration as a SAML Service Provider or Identity Provider with Gateway or AAA authentication. The content reports active exploitation and CISA KEV inclusion. Citrix describes the impact as DoS; initial third-party claims of remote code execution remain disputed. Fixes are listed as 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 for the applicable branches. Citrix-provided Global Deny List signatures are described as an interim mitigation.
An actively exploited memory-overflow vulnerability affecting customer-managed NetScaler appliances configured as a SAML service provider or identity provider. It has a CVSS v4.0 score of 8.7 and permits unauthenticated network attacks without user interaction. Confirmed effects are denial of service, including repeated crashes that can sustain outages. Reports suggest possible code execution, but the content does not establish it as a confirmed capability of this CVE or establish successful data theft. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28; ADC 14.1 FIPS before 14.1-73.41 FIPS; and ADC 13.1 FIPS and NDcPP before 13.1-37.282. Updates to those fixed builds or later are available. Previously patched deployments may still require another update. Citrix also provides Global Deny Lists to block known malicious IP addresses, but urges prompt patching.
A memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication with Gateway or AAA functionality. Rated CVSS 8.7, it is actively exploited to cause repeated crashes and service outages. Researchers reported attempted shell-command execution and a downloaded malware binary running on a patched honeypot, but successful remote code execution through this specific flaw remains under investigation. Citrix released emergency patches, provided Global Deny Lists, and recommended immediate updating. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
A high-severity memory-management vulnerability that could allow a remote, unauthenticated attacker to cause denial of service under certain conditions. Only NetScaler instances configured as a SAML Service Provider or Identity Provider are vulnerable. Affected releases include ADC and Gateway 13.1 before 13.1-64.28 and 14.1 before 14.1-73.41; ADC FIPS 14.1 before 14.1-73.41 FIPS; and ADC FIPS and NDcPP 13.1 before 13.1-37.282. Secure Private Access Hybrid deployments using affected NetScaler instances are also affected. Exploitation attempts were observed, but the report does not establish successful compromise and states that no evidence of data-integrity compromise had been detected. Administrators should install the corrective releases, including on vulnerable instances previously updated to 14.1-73.37 or 13.1-64.23. Relevant SAML configuration directives are 'add authentication samlAction' and 'add authentication samlIdPProfile'.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.