Use Citrix NetScaler with SAML login? Patch it now
Businesses using Citrix NetScaler ADC or NetScaler Gateway specifically configured for SAML single sign-on. This is a different, newer flaw to the one in our 28 September briefing, so having patched that one doesn't cover this. If your NetScaler isn't set up for SAML login, or you don't run NetScaler at all, this one doesn't apply to you.
Citrix has confirmed criminals are already using a flaw in NetScaler ADC and NetScaler Gateway to crash the SAML (Security Assertion Markup Language) single sign-on feature many businesses use to let staff log in to multiple apps with one company account. The US Cybersecurity and Infrastructure Security Agency added it to its must-patch list on 4 October 2026 with an unusually tight three-day deadline for government agencies, a sign of how seriously it's being taken. The flaw only affects NetScaler devices specifically set up for SAML login, either as the identity provider or the service provider; other NetScaler setups are not affected by this particular issue.
Do this
Ask your IT provider: "Is our Citrix NetScaler set up for SAML login, and has it been updated to 14.1-73.41, 13.1-64.28, or later?"
Sources: CISA Known Exploited Vulnerabilities Catalog ↗ · Citrix security bulletin CTX697174 ↗CVE-2026-88779 · CWE-119