# Researchers Flag NetScaler SAML Exploitation

A security post reports a second NetScaler exploitation method involving SAML requests that may remain effective after remediation of CVE-2026-88771 and CVE-2026-88772. Citrix says the issue is independent of the vulnerabilities disclosed in CTX697096. The post also points to community reports with indicators of compromise and accounts of scan-triggered reboots; it identifies no government agency, contract, or specific public-sector impact.

- Government buyers and contractors using NetScaler should not assume that remediation of the cited CVEs also addresses the separately reported SAML method; assess whether NetScaler appliances are in their environments.
- Security teams and service providers can use the cited community IoCs to inform their investigation and consider the reported scan-triggered reboots when assessing operational impact.
- The signal indicates a security-assurance concern for organizations relying on NetScaler, rather than a defined procurement opportunity or new government requirement.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 03, 2026

### Vendors
- Citrix (NetScaler product manufacturer)

### Key Quotes
> It seems like the vulnerability from sunday (CVE-2026-88771 and CVE-2026-88772) isn't fully fixed.
> — Original poster

> This issue is independent of the vulnerabilities disclosed in CTX697096.
> — Citrix

### Sources
- [Netscaler Pitscaler Vulnerability 2.0](https://www.reddit.com/r/cybersecurity/comments/1wws05m/netscaler_pitscaler_vulnerability_20) - reddit-cybersecurity