CRITICALZero Day
Global

Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

·Source: CSO Online

Updated:

Executive Summary

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days . The new vulnerability, tracked as CVE-2026-88779 , is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Cit

Analysis

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days . The new vulnerability, tracked as CVE-2026-88779 , is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Citrix rated it 8.7 under CVSS 4.0 and said it has observed targeted attacks against unmitigated NetScaler deployments. The company said the attacks can repeatedly trigger the condition, potentially leaving the service unavailable. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met,” the company said in a blog post . “Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible.” Citrix has not attributed the activity to a particular threat actor or provided technical details on how the vulnerability is being exploited. “The reality is that the focus on edge appliances as an easy access mechanism to organizations is not changing,” said watchTowr founder Benjamin Harris , who was among the first to warn about the recent Citrix zero-days. “Attackers are well aware that there is more to be found in these types of appliances in terms of vulnerabilities.” Exploitation needs a precondition The flaw is not present in every NetScaler deployment. It requires the appliance to be configured for SAML authentication , either as a SAML service provider or identity provider, with the relevant SAML functionality used alongside Gateway or AAA virtual servers. CVE-2026-88779 affects NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1-64.28, as well as 14.1 FIPS before 14.1-73.41 FIPS and 13.1 FIPS/NDcPP before 13.1-37.282. Citrix said Secure Private Access Hybrid deployments using NetScaler instances are affected and must be upgraded. Administrators were advised to check for “add authentication samlAction” and “add authentication samlIdPProfile” entries in their configurations to determine whether the precondition applies. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data,” Citrix said. NetScaler customers may have to patch twice in a week The timing is concerning for enterprises that have just completed Citrix’s previous emergency patch cycle. Last week, Citrix disclosed eight NetScaler vulnerabilities, including CVE-20206-88771 and CVE-2026-88772 , two critical flaws that the company said were already being exploited. The fixes affected 14.1 deployments to 14.1-73.37 and 13.1 deployments to 13.1-64.23. However, Citrix now says organizations that installed those releases must upgrade again if their appliances meet the SAML preconditions for CVE-2026-88779. The new fixed versions are 14.1-73.41, 13.1-64.28, 4.1-73.41 FIPS, and 13.1-37.282 for the applicable FIPS and NDcPP builds. There is a temporary mitigation for some already-patched deployments. Citrix says Global Deny List signatures can reduce exposure on NetScaler versions 14.1-73.37 through 73.40 and 13.1-64.23 through 64.27, provided the relevant virtual-patching functionality is enabled. Customers relying on this mitigation must verify if Global Deny List signatures are available on their NetScaler deployments by executing the “show appfw signatures” command. Upgrading to the fixed builds, however, remains necessary wherever possible, the company noted. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, listing October 7 as the remediation deadline for US federal agencies.

Indicators of Compromise (2)

CVE (2)
CVE-2026-88779
CVE-2026-88772
Source Attribution

Originally published by CSO Online on Oct 5, 2026.

Related Threats

CRITICALZero Day

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate AI-powered workflows without writing much code — are landing in production environments faster than security teams can assess them. They connect to your APIs, your databases, your cloud credentials and yo

CVE-2026-0768CVE-2026-0769
CSO Online
CRITICALZero Day

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested by the FBI and has been cooperating

CVE-2026-35273
CSO Online
CRITICALZero Day

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the F

CVE-2026-35273
CSO Online