Impact 9 out of 10
Issue #1
Exploited NetScaler SAML flaw joins CISA's KEV list; federal deadline is today
Event date
Show facts, unknowns, and opinionHide story sections
Facts
CISA added CVE-2026-88779 (Citrix NetScaler ADC/Gateway) to its Known Exploited Vulnerabilities catalog on Oct. 4. Federal civilian agencies were given until Oct. 7 and must run forensic triage under BOD 26-04.
Citrix calls it a memory-overflow bug that causes denial of service on customer-managed appliances set up as a SAML service provider or identity provider. CVSS v4 score: 8.7. Fixed builds: 14.1-73.41 and 13.1-64.28, plus FIPS/NDcPP builds.
Citrix says it has seen targeted attacks and that repeated triggering can keep the service down. It says it has found no impact on customer data integrity.
The flaw follows two other NetScaler bugs (CVE-2026-88771, -88772) that CISA added to the KEV catalog on Sept. 27. Some admins reported crashes after patching for them.
Unknowns
- Researchers have not yet established whether this flaw can lead to remote code execution, beyond crashing the appliance.
- Who is behind the attacks, and whether ransomware crews use the flaw (CISA lists ransomware use as 'Unknown').
Why it matters for builders and gov entrants
Selling to or working inside federal agencies? Expect primes and contracting officers to ask for patch evidence and forensic-triage notes on edge devices. Have them ready before anyone asks.
Sources
Published Accessed
Published Accessed
Published Accessed
Published Accessed