U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog
CISA added exploited Citrix NetScaler flaw CVE-2026-88779 to KEV, with federal fixes due October 7.
CISA added Citrix NetScaler CVE-2026-88779, a CVSS 8.7 memory-overflow flaw in customer-managed ADC and Gateway, to the Known Exploited Vulnerabilities catalog. Exploitation requires a SAML service-provider or identity-provider configuration and can cause denial of service; Citrix has seen targeted attacks but reports no impact on data integrity. Patches are available in 14.1-73.41, 13.1-64.28, and corresponding FIPS and NDcPP releases, while Citrix-managed cloud services are already updated. Federal agencies must remediate by October 7, 2026.
- CVE-2026-88779 is a NetScaler memory overflow rated CVSS 8.7.
- Attacks require SAML service-provider or identity-provider configuration.
- Citrix observed targeted denial-of-service attacks, with no data-integrity impact.
- Fixes include 14.1-73.41, 13.1-64.28, and listed FIPS builds.
- CISA orders federal agencies to remediate by October 7, 2026.
Vulnerabilities mentionedAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article488 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions. It affects certain customer-managed deployments running vulnerable versions.
“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” reads the advisory. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”
Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP). Customers can check their configuration for the relevant SAML settings.
Below are the impacted versions:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28
- NetScaler ADC FIPS before 14.1-73.41 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.282
Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service. Repeated exploitation may keep the affected service unavailable, but Citrix has not identified any impact on customer data integrity.
“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable.” continues the advisory. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data. Citrix strongly urges all customers to install the latest versions as soon as possible.”
The company urges customers to install the latest versions as soon as possible. Exposure depends on the deployment configuration, particularly whether NetScaler uses SAML with Gateway or AAA functionality. Customers should check their configurations for SAML authentication settings, including add authentication samlAction for a SAML service provider or add authentication samlIdPProfile for a SAML identity provider. The bulletin applies only to customer-managed NetScaler ADC and Gateway deployments; Citrix-managed cloud services have already been updated.
The following versions fix the issue:
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by October 7, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)