By Shweta Sharma
Publication Date: 2026-10-05 12:14:00
“Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data,” Citrix said.
NetScaler customers may have to patch twice in a week
The timing is concerning for enterprises that have just completed Citrix’s previous emergency patch cycle. Last week, Citrix disclosed eight NetScaler vulnerabilities, including CVE-20206-88771 and CVE-2026-88772, two critical flaws that the company said were already being exploited. The fixes affected 14.1 deployments to 14.1-73.37 and 13.1 deployments to 13.1-64.23.
However, Citrix now says organizations that installed those releases must upgrade again if their appliances meet the SAML preconditions for CVE-2026-88779. The new fixed versions are 14.1-73.41, 13.1-64.28, 4.1-73.41 FIPS, and 13.1-37.282 for the applicable FIPS and NDcPP builds.


