CVE-2026-88779: Citrix NetScaler SAML Memory Overflow Zero-Day Added to CISA KEV
CVE-2026-88779 (CWE-119 / CWE-120)
Severity: HIGH (CVSS 8.7)
Status: Actively Exploited Zero-Day (Added to CISA KEV Oct 4, 2026; BOD 26-04 Deadline: Oct 7)
Affected Systems: NetScaler ADC and NetScaler Gateway 14.1 (< 14.1-73.41), 13.1 (< 13.1-64.28)
Fixed In: NetScaler ADC/Gateway 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 NDcPP
On October 4, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive adding CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Following hot on the heels of the late-September dual zero-days (CVE-2026-88771/72), this vulnerability represents an improper restriction of operations within the bounds of a memory buffer (CWE-119) inside the NetScaler packet engine daemon (nsppe) when handling Security Assertion Markup Language (SAML) assertions. Citrix has confirmed active, targeted in-the-wild exploitation against customer-managed appliances configured as SAML Service Providers (SP) or Identity Providers (IdP).
Technical Root Cause Analysis
The vulnerability exists within the SAML parser library embedded in the NetScaler Packet Processing Engine (nsppe). When an appliance is configured to act as a SAML Service Provider (via add authentication samlAction) or as an Identity Provider (via add authentication samlIdPProfile), the NetScaler HTTP daemon passes inbound XML payloads to an internal unmarshaling routine.
During the extraction of base64-encoded <samlp:Response> or <saml:Assertion> attributes, the routine calculates the allocation size based on the unpadded length of the input string rather than the fully expanded UTF-8 byte stream resulting from entity expansion. When an attacker sends an oversized or malformed XML attribute structure, the buffer allocation is insufficient:
/* Decompiled abstraction of vulnerable SAML attribute decode routine in nsppe */
int parse_saml_assertion_attribute(char *xml_buffer, size_t input_len) {
char decoded_attr[1024]; // Fixed stack buffer
size_t expected_size = calculate_base64_len(xml_buffer, input_len);
// VULNERABILITY: Integer truncation check fails when input exceeds 65535 bytes
if ((uint16_t)expected_size > sizeof(decoded_attr)) {
// Log truncated warning, but proceed with decoding using unchecked size!
ns_log(LOG_ERR, "SAML attribute exceeds standard size");
}
// Unchecked memory copy into fixed buffer triggers heap/stack memory overflow
return base64_decode_stream(xml_buffer, decoded_attr, expected_size);
}
Because the bounds-check operates on a 16-bit integer cast, crafting a payload where expected_size & 0xFFFF is less than 1024 causes the safety check to succeed. The subsequent decode operation writes hundreds of contiguous bytes past the allocated boundary, corrupting adjacent heap metadata and pointer structures within the packet engine. This causes an immediate denial of service (DoS) by crashing nsppe, and under specific memory layouts, permits memory manipulation and code execution.
Vulnerable Configuration Preconditions
NetScaler instances are vulnerable if their active configuration contains either of the following directives:
# SAML Service Provider Configuration
add authentication samlAction "Corp_SAML_SP" -samlIdPCertName "idp_cert" -samlRedirectUrl "https://idp.example.com/sso"
# SAML Identity Provider Configuration
add authentication samlIdPProfile "Corp_SAML_IdP" -samlSPCertName "sp_cert" -samlIdPCertName "idp_cert"
Appliances not utilizing SAML authentication or operating strictly as standard L4/L7 load balancers without AAA features are not vulnerable to this specific attack vector.
Detection Telemetry & Threat Hunting
Network defenders must immediately inspect NetScaler syslog feeds and crash directories for anomalous packet engine failures:
# Check if SAML SP or IdP is configured
grep -E "add authentication samlAction|add authentication samlIdPProfile" /nsconfig/ns.conf
# Check for nsppe core dumps generated in the past 72 hours
shell "ls -lt /var/core/nsppe* 2>/dev/null"
# Query auth syslog for malformed SAML decode anomalies
shell "zgrep -E 'SAML attribute exceeds|assertion decode error' /var/log/ns.log*"alert http any any -> $NETSCALER_VIP any (msg:"COLIBRISEC - Citrix NetScaler CVE-2026-88779 Oversized SAML Assertion"; flow:to_server,established; content:"POST"; http_method; content:"SAMLResponse="; http_client_body; pcre:"/SAMLResponse=[A-Za-z0-9%+/]{65500,}/"; classtype:attempted-admin; sid:20260401; rev:1;)Remediation & Mitigation Protocol
- Apply Official Firmware Hotfix: Upgrade immediately to NetScaler ADC and Gateway 14.1-73.41 or 13.1-64.28. Note that if you recently patched for CVE-2026-88771/72, you must still apply this update.
- Deploy Global Deny List Mitigation: If patching cannot be completed immediately, implement Citrix Global Deny List signatures targeting malformed SAML assertion headers.
- Isolate AAA Virtual Servers: Place management interfaces and SAML endpoints behind an auxiliary web application firewall (WAF) enforcing strict HTTP POST body size limits (< 32 KB) on SAML assertion endpoints.