Citrix NetScaler Flaw Exploited as CISA Sets October 7 Deadline
Citrix says it has observed targeted attacks exploiting a NetScaler vulnerability that can disrupt service availability, while the U.S. Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog and set an October 7 remediation deadline for federal agencies. The vulnerability, CVE-2026-88779, is a memory overflow issue affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments running vulnerable supported versions. Citrix says exploitation can cause a denial-of-service condition and, if triggered repeatedly, may leave an affected service unavailable. The company says it has not identified an impact on customer data integrity. The reported risk depends on configuration rather than applying to every deployment. Citrix says the appliance must be configured for SAML authentication as either a service provider or identity provider, with relevant SAML functionality used alongside Gateway or AAA virtual servers. Administrators can check for the configuration entries add authentication samlAction and add authentication samlIdPProfile, according to the guidance described in the reports.