CISA Adds a Citrix NetScaler Flaw to Its Exploited List a Day After the Fix Shipped

Citrix published fixed builds on Oct. 3 for a vulnerability in its NetScaler ADC and NetScaler Gateway appliances, and a day later the US Cybersecurity and Infrastructure Security Agency added that flaw to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.
The catalog is CISA's public list of flaws it has evidence attackers are using, and it is the trigger for the agency's patching rules. CISA's alert says Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of cataloged flaws on publicly exposed systems that would give an attacker full control, and to defer lower-risk ones; it encourages all other organizations to work from the catalog as well. Citrix's own bulletin does not say the flaw has been used in attacks. That finding is CISA's.
Citrix describes CVE-2026-88779 as a memory overflow leading to a denial of service and rates it 8.7 on the CVSS v4.0 severity scale. An appliance is exposed only if it has been configured as a SAML service provider or a SAML identity provider, the settings that let a NetScaler broker single sign-on logins for other applications. A denial of service means such an appliance can be driven to stop working, not to hand over data or run an attacker's code.
Citrix urged customers to install the fixed builds as soon as possible: 14.1-73.41 and 13.1-64.28, and later, with separate builds for appliances certified to the FIPS and NDcPP standards. The bulletin covers customer-managed appliances only; the Citrix-managed cloud services are updated by the company itself. Secure Private Access Hybrid deployments that use NetScaler instances need the new builds too.
Citrix credits the security firms Bishop Fox and watchTowr with reporting the flaw.
