U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog.The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog.CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions. It affects certain customer-managed deployments running vulnerable versions.“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” reads the advisory. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP). Customers can check their configuration for the relevant SAML settings.Below are the impacted versions:NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.41 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.28 NetScaler ADC FIPS before 14.1-73.41 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.282 Citrix says it has observed targeted attacks against unpatched deployments that can cause denial of service. Repeated exploitation may keep the affected service unavailable, but Citrix has not identified any impact on customer data integrity. “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable.” continues the advisory. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data. Citrix strongly urges all customers to install the latest versions as soon as possible.”The company urges customers to install the latest versions as soon as possible. Exposure depends on the deployment configuration, particularly whether NetScaler uses SAML with Gateway or AAA functionality. Customers should check their configurations for SAML authentication settings, including add authentication samlAction for a SAML service provider or add authentication samlIdPProfile for a SAML identity provider. The bulletin applies only to customer-managed NetScaler ADC and Gateway deployments; Citrix-managed cloud services have already been updated.The following versions fix the issue:NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releasesNetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPSNetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPPAccording to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.CISA orders federal agencies to fix the flaw by October 7, 2026.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, CISA)