The exposed set is broader than a single SAML login path. Citrix has now patched multiple NetScaler roles, so a box can still be vulnerable in one enabled function even if another function is already fixed; partial patching leaves some control-plane paths open.
The fixes cover NetScaler ADC and NetScaler Gateway 14.1-72.61 and 13.1-63.18, plus 14.1-72.61 FIPS and 13.1.37.272 for FIPS/NDcPP builds. The six CVEs span SAML IdP, Gateway, load-balancing, HTTP/2, and related parsing flaws, with impact ranging from memory overread and memory overflow to arbitrary file read and denial of service.
That changes the usual appliance assumption. On a multi-role NetScaler, security now depends on every configured service being patched, not just the one that first drew attention.