Summary
- CVE-2026-88779 is a memory overflow vulnerability with a CVSS v4 score of 8.7.
- Exploitation can cause denial of service on NetScaler systems configured as a SAML service provider or identity provider.
- NHS England says the flaw is being exploited and continued attacks are highly likely.
NHS England has warned health and care organisations that attackers are exploiting a newly disclosed NetScaler vulnerability capable of causing denial of service on systems configured for particular SAML authentication roles.
CVE-2026-88779 is a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway. The vendor assigns it a CVSS v4 score of 8.7, while NHS England’s National Cyber Security Operations Centre has classified its alert as medium severity.
The vulnerability applies where an affected NetScaler system is configured as either a SAML service provider or a SAML identity provider. Successful exploitation can cause the service to become unavailable.
NHS England said the vulnerability had been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue and assessed continued exploitation as highly likely.
CVE-2026-88779 is separate from the NetScaler vulnerabilities covered extensively in late September and early October. Those incidents centred on CVE-2026-88771 and CVE-2026-88772, which included remote code execution and evidence of persistent attacker access.
A separate flaw adds to the NetScaler remediation burden
Administrators who have already responded to the earlier vulnerabilities therefore face a different issue rather than an extension of the same CVE. The conditions required for exploitation and the resulting impact are not the same.
CVE-2026-88779 affects availability. It does not provide the remote code execution capability described in the earlier NetScaler disclosures, but denial of service can still disrupt access where the appliance sits in front of authentication, remote access or business applications.
NHS England lists NetScaler ADC and Gateway 14.1 releases before 14.1-73.41 and 13.1 releases before 13.1-64.28 among the affected products. Relevant FIPS and NDcPP editions are also affected below the corrected versions specified in the advisory.
Secure Private Access Hybrid deployments using NetScaler instances are included. Customer-managed appliances require action by the organisation operating them.
NHS England directs affected organisations to install the vendor’s corrected releases. Its alert also reflects the particular exposure of network edge products, which have to accept connections from external networks in order to provide the services for which they are deployed.
The 8.7 CVSS score and the NHS medium severity label measure different things. CVSS describes characteristics of the vulnerability, while the NHS classification reflects the alert within its own operational framework.
Inclusion in the exploited vulnerability catalogue moves the evidence beyond a theoretical flaw. Attackers have used CVE-2026-88779, although the approved sources do not identify the affected organisations or quantify how widely exploitation has occurred.
The new alert does not add evidence about CVE-2026-88771 or CVE-2026-88772. Organisations that already patched those vulnerabilities still need to assess whether their systems meet the conditions for CVE-2026-88779.
NHS England published the alert on 5 October and says further exploitation is highly likely, making the issue directly relevant to health organisations operating affected NetScaler systems.




