CISA flags exploited NetScaler flaw CVE-2026-88779
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog: a memory overflow in Citrix NetScaler ADC and Gateway that causes denial of service. Attacks target only deployments using SAML authentication; US federal agencies must remediate by October 7.
- CVE-2026-88779 is a memory overflow causing NetScaler denial of service
- Affected: versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28
- Exploitation requires SAML authentication configured on the appliance
- CISA orders US federal agencies to fix by October 7
Read next
Security