7IT · News

CISA flagged a NetScaler login flaw on Sunday. Federal agencies get three days.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Sunday, 4 October 2026, CISA added CVE-2026-88779 in Citrix NetScaler ADC and Gateway to its list of exploited flaws, with a 7 October deadline for federal agencies. The memory flaw (CVSS 8.7) hits appliances set up as a SAML service provider or identity provider. Fixed builds: 14.1-73.41 and 13.1-64.28.

Why it matters

Citrix calls it an availability bug and confirms targeted attacks on unpatched appliances. BleepingComputer reports researchers saw attempts to download and run code through it. And that box is the front door for your remote logins.

What to do

If you run NetScaler with SAML, check it for signs of compromise, then upgrade to 14.1-73.41 or 13.1-64.28 (or the matching FIPS build) today.

Two NetScaler alarms a week apart. When the same front door keeps making the news, I stop asking if it's patched and start asking who already came in.

Lior Aharonov · my take

Sources

securitycisa kevcitrix

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.