CVE-2026-88779 is a memory overflow vulnerability in the SAML processing of customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML service providers or identity providers. Unauthenticated remote attackers can trigger authentication-service crashes, appliance reboots, and denial of service without user interaction. Affected releases precede 14.1-73.41 and 13.1-64.28 in the standard branches, 14.1-73.41 FIPS in the ADC 14.1-FIPS branch, and 13.1-37.282 in the ADC 13.1-FIPS and 13.1-NDcPP branches. Relevant Secure Private Access Hybrid deployments are also affected. The vulnerability was exploited as a zero-day. The exact triggering request and vulnerable memory operation have not been publicly disclosed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
258 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploited Citrix NetScaler memory-overflow vulnerability affecting SAML configurations, with a reported severity score of 8.7. It is discussed as context for the newer critical NetScaler disclosure. The content does not specify its precise exploitation impact or patch availability.
A memory overflow vulnerability affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway deployments configured as SAML Service Providers or Identity Providers. Successful exploitation can cause denial of service. Its addition to CISA's Known Exploited Vulnerabilities catalog indicates known exploitation.
A NetScaler vulnerability under confirmed active exploitation. Its technical characteristics and affected builds are not provided. The article recommends applying fixes from the separate Citrix advisory and performing a compromise assessment.
A vulnerability affecting NetScaler ADC and NetScaler Gateway, mentioned as background because it is actively exploited. Its technical details are not provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.