Skip to content
See the World Through ScienceA project of ALLATRA

CISA Adds a Citrix NetScaler Flaw to Its Exploited List a Day After the Fix Shipped

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Bundles of orange and yellow network cables plugged into the rear of a rack mounted patch panel.
Rack cabling in an enterprise network, the setting where NetScaler appliances broker single sign-on logins (illustrative)."Ethernet Patch Panel - Rear" by dmitrybarsky, via flickr, CC-BY-2.0

Citrix published fixed builds on Oct. 3 for a vulnerability in its NetScaler ADC and NetScaler Gateway appliances, and a day later the US Cybersecurity and Infrastructure Security Agency added that flaw to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.

The catalog is CISA's public list of flaws it has evidence attackers are using, and it is the trigger for the agency's patching rules. CISA's alert says Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of cataloged flaws on publicly exposed systems that would give an attacker full control, and to defer lower-risk ones; it encourages all other organizations to work from the catalog as well. Citrix's own bulletin does not say the flaw has been used in attacks. That finding is CISA's.

Citrix describes CVE-2026-88779 as a memory overflow leading to a denial of service and rates it 8.7 on the CVSS v4.0 severity scale. An appliance is exposed only if it has been configured as a SAML service provider or a SAML identity provider, the settings that let a NetScaler broker single sign-on logins for other applications. A denial of service means such an appliance can be driven to stop working, not to hand over data or run an attacker's code.

Citrix urged customers to install the fixed builds as soon as possible: 14.1-73.41 and 13.1-64.28, and later, with separate builds for appliances certified to the FIPS and NDcPP standards. The bulletin covers customer-managed appliances only; the Citrix-managed cloud services are updated by the company itself. Secure Private Access Hybrid deployments that use NetScaler instances need the new builds too.

Citrix credits the security firms Bishop Fox and watchTowr with reporting the flaw.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

CISA Adds a Citrix NetScaler Flaw to Its Exploited List a Day After the Fix Shipped

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.