Skip to content
cve — cve-2026-88772

grep -rl "CVE-2026-88772" ./articles

CVE-2026-88772

Citrix shipped 14.1-73.37 for two actively exploited 9.5s. Customers who installed it are reporting repeated appliance reboots, traced to crafted SAML traffic crashing the authentication service until the watchdog restarts the box. Citrix says it is tracking a newly seen SAML issue. Bulletin CTX697096, last updated 27 September, still does not mention it.

2 articles — 2026-10-01 to 2026-10-03

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it

2026-10-03Security

Citrix shipped 14.1-73.37 for two actively exploited 9.5s. Customers who installed it are reporting repeated appliance reboots, traced to crafted SAML traffic crashing the authentication service until the watchdog restarts the box. Citrix says it is tracking a newly seen SAML issue. Bulletin CTX697096, last updated 27 September, still does not mention it.

../cve — every identifier we have covered