CISA flagged a NetScaler login flaw on Sunday. Federal agencies get three days.
By Lior AharonovFounder, 7IT Solutions ·
On Sunday, 4 October 2026, CISA added CVE-2026-88779 in Citrix NetScaler ADC and Gateway to its list of exploited flaws, with a 7 October deadline for federal agencies. The memory flaw (CVSS 8.7) hits appliances set up as a SAML service provider or identity provider. Fixed builds: 14.1-73.41 and 13.1-64.28.
Citrix calls it an availability bug and confirms targeted attacks on unpatched appliances. BleepingComputer reports researchers saw attempts to download and run code through it. And that box is the front door for your remote logins.
If you run NetScaler with SAML, check it for signs of compromise, then upgrade to 14.1-73.41 or 13.1-64.28 (or the matching FIPS build) today.
Two NetScaler alarms a week apart. When the same front door keeps making the news, I stop asking if it's patched and start asking who already came in.
Lior Aharonov · my takeSources
Researched with AI tools; every fact is checked against the linked sources.