# Citrix releases NetScaler fixes as CISA sets October 7 mitigation deadline

_Published Sunday, October 4, 2026 at 7:06 PM EDT · Security · Latest · Tier 2 — Notable_

![Citrix releases NetScaler fixes as CISA sets October 7 mitigation deadline — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/27/Citrix.jpg)

Citrix released emergency NetScaler updates on Sunday for CVE-2026-88779, a memory buffer flaw exploited in targeted attacks, BleepingComputer reported. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal civilian executive branch agencies until October 7 to mitigate it.

The flaw affects NetScaler ADC and Gateway appliances configured for SAML authentication with Gateway or AAA functionality. Repeated exploitation can keep services unavailable. Affected organizations that installed fixes for earlier vulnerabilities must upgrade again; Citrix released versions 14.1-73.41 and 13.1-64.28, with separate instructions for FIPS deployments.

Researchers are investigating possible remote code execution. Citrix describes the confirmed impact as denial of service and says it has identified no impact on customer data integrity.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/k9IvHU6mI45MzigntxPHyw
Published: 2026-10-04T23:06:09.777Z
Story chronology: 2026-10-04T21:58:01.000Z
Retrieved: 2026-10-05T00:45:27.461Z
Publisher: Tech & Business (techandbusiness.org)
