securityaffairs.com 5 Oct 2026, 13:10 UTC

CISA Flags Exploited Citrix NetScaler Flaw That Can Take Services Offline

CISA Flags Exploited Citrix NetScaler Flaw That Can Take Services Offline
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Citrix NetScaler flaw to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, tracked as CVE-2026-88779, is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway with a CVSS score of 8.7. It can cause a denial-of-service condition under specific deployment scenarios and affects customer-managed NetScaler deployments running affected versions when particular preconditions are met.

Exploitation requires the NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP). Citrix has reported targeted attacks against unpatched, misconfigured deployments, which can render the service unavailable if the condition is triggered repeatedly. The advisory notes there is no identified impact on the integrity of customer data.

The affected versions are NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, NetScaler ADC FIPS before 14.1-73.41 FIPS, and NetScaler ADC FIPS/NDcPP before 13.1-37.282. The fixes are in 14.1-73.41 and later, 13.1-64.28 and later of 13.1, 14.1-FIPS 14.1-73.41 FIPS and later, and 13.1-FIPS/13.1-NDcPP 13.1-37.282 and later.

CISA requires federal agencies to remediate by 7 October 2026 under BOD 22-01, with guidance for private organisations to review the KEV catalog and apply fixes. Citrix advises customers to update to the latest versions and to verify SAML configurations, including add authentication samlAction for SP or samlIdPProfile for IdP deployments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline