Early Sunday morning Citrix shipped fixed NetScaler ADC and Gateway builds for CVE-2026-88779, and CISA listed it the same day. Citrix’s sentence: a memory overflow that can lead to denial of service when the appliance is configured as a SAML service provider or identity provider. Citrix says it has seen targeted attacks on unmitigated deployments that can knock the service offline, and its analysis points to availability impact without an identified hit on customer-data integrity. Federal civilian agencies are due Wednesday, October 7. That date is in the catalog. Ransomware use is listed as unknown.
If that gateway is yours and SAML is on, install Sunday’s build from Citrix’s bulletin: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282 for 13.1-FIPS/NDcPP. Secure Private Access Hybrid deployments that use NetScaler are in scope too. The September 28 updates for the earlier NetScaler bugs do not cover this one — if SAML is configured, upgrade again. Some researchers are still arguing about possible code execution; Citrix’s published finding is denial of service. Do not treat those arguments as confirmed RCE. People who do not run NetScaler have nothing to install.
A separate note, not a password reset. Over the weekend reporting citing Reuters said a suspected ShinyHunters member known as “Rey” (identified as Saif al-Din Khader) was detained in Jordan and is cooperating with the FBI. That is awareness, not an install step. Do not pay an extortion demand because a brand-name crew looks disrupted, and do not assume disruption means stolen SaaS data is gone. Ordinary consumers: ignore anyone claiming to be “Rey,” “ShinyHunters,” or “FBI recovery” and asking for money, crypto, or a recovery phrase.