Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Used in attacksCriticalSecurityWeek · Eduard Kovacs·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-88779
Vendors and products
Citrix
Reported by
1 outlet

Citrix NetScaler administrators scrambled over the weekend to protect their appliances after exploitation of a new zero-day vulnerability began.

Administrators initially reported reboots of fully patched NetScaler systems on Friday, and Citrix soon confirmed the existence of another zero-day exploited in the wild.

According to Citrix, the new vulnerability, tracked as CVE-2026-88779 and classified as high severity, is a memory overflow issue affecting NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP. 

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix explained in a blog post. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

The attacks were spotted just days after NetScaler administrators were warned about two actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772, which forced some customers to pull the plug. 

While Citrix describes CVE-2026-88779 as a DoS vulnerability, there is some indication it may also be exploitable for remote code execution. 

Advertisement. Scroll to continue reading.

Security researcher Kevin Beaumont, who dubbed the vulnerability PitScaler 2 (CVE-2026-88771 and CVE-2026-88772 are dubbed PitScaler), confirmed seeing exploitation attempts against patched honeypot instances. Beaumont also reported that one of his honeypots was running a downloaded malware binary.

Reddit users initially reported that NetScaler appliances already updated to the latest version in response to the CVE-2026-88771 and CVE-2026-88772 attacks kept rebooting. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field and meant to fetch and run a malicious script.

One user who obtained the script said it tries to plant web shells, survive reboots, and upload the appliance’s configuration and backups, but cautioned that there was no proof the script actually ran.

Before patches arrived, admins complained about support queues that lasted hours and about interim workarounds that sometimes failed to stop the crashes.

CISA added CVE-2026-88779 to its KEV catalog on October 4, instructing federal agencies to address it by October 7. This is the sixth exploited NetScaler vulnerability CISA added to its catalog in 2026.

Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Originally published by SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.

Vulnerabilities referenced

  • CVE-2026-88779Not scored yet

    Citrix NetScaler

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

    Used in attacks

    Added to CISA's list 2026-10-04

    Full record →

Fastnexa security experts

This story involves a flaw attackers are already using. Are you exposed?

A Fastnexa penetration tester can check whether CVE-2026-88779 or anything like it can be used against your websites, apps and network.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. SecurityWeek ↗Established SourceFirst reported

    2026-10-05 05:14 UTC

Related stories