Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-88779
- Vendors and products
- Citrix
- Reported by
- 1 outlet
Citrix NetScaler administrators scrambled over the weekend to protect their appliances after exploitation of a new zero-day vulnerability began.
Administrators initially reported reboots of fully patched NetScaler systems on Friday, and Citrix soon confirmed the existence of another zero-day exploited in the wild.
According to Citrix, the new vulnerability, tracked as CVE-2026-88779 and classified as high severity, is a memory overflow issue affecting NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP.
“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix explained in a blog post. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”
The attacks were spotted just days after NetScaler administrators were warned about two actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772, which forced some customers to pull the plug.
While Citrix describes CVE-2026-88779 as a DoS vulnerability, there is some indication it may also be exploitable for remote code execution.
Advertisement. Scroll to continue reading.
Security researcher Kevin Beaumont, who dubbed the vulnerability PitScaler 2 (CVE-2026-88771 and CVE-2026-88772 are dubbed PitScaler), confirmed seeing exploitation attempts against patched honeypot instances. Beaumont also reported that one of his honeypots was running a downloaded malware binary.
Reddit users initially reported that NetScaler appliances already updated to the latest version in response to the CVE-2026-88771 and CVE-2026-88772 attacks kept rebooting. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field and meant to fetch and run a malicious script.
One user who obtained the script said it tries to plant web shells, survive reboots, and upload the appliance’s configuration and backups, but cautioned that there was no proof the script actually ran.
Before patches arrived, admins complained about support queues that lasted hours and about interim workarounds that sometimes failed to stop the crashes.
CISA added CVE-2026-88779 to its KEV catalog on October 4, instructing federal agencies to address it by October 7. This is the sixth exploited NetScaler vulnerability CISA added to its catalog in 2026.
Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild
Originally published by SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.
Vulnerabilities referenced
- CVE-2026-88779Not scored yet
Citrix NetScaler
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Used in attacksAdded to CISA's list 2026-10-04
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-88779 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-05 05:14 UTC
Related stories
- Citrix patches NetScaler SAML zero-day exploited in attacks
BleepingComputer · 2026-10-04 · exploited
- Xray-core concealed a certificate verification bypass vulnerability
Hacker News · 2026-10-04
- Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force
SecurityWeek · 2026-10-04
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The Hacker News · 2026-10-03