Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix NetScaler Appliances Hit by Another Zero-Day Vulnerability, Just Days After Previous Patch

Citrix administrators are once again scrambling to protect their appliances from a new zero-day vulnerability that has been exploited in the wild. This latest threat is particularly concerning, as it affects systems that were already patched just days earlier against two other actively exploited vulnerabilities.

According to Citrix, the new vulnerability (CVE-2026-88779) is a memory overflow issue affecting NetScaler ADC and Gateway instances configured as SAML Service Providers or Identity Providers. The vulnerability is considered high-severity and can lead to Denial of Service (DoS), which means that affected systems may become unavailable if exploited repeatedly.

Citrix has observed targeted attacks on unmitigated NetScaler deployments, which suggests that attackers are actively exploiting this vulnerability. The company’s analysis indicates that the issue affects service availability rather than data integrity. However, security researcher Kevin Beaumont has reported seeing exploitation attempts against patched honeypot instances, and one of his honeypots was found to be running a malicious binary.

The attacks have been spotted just days after Citrix administrators were warned about two other zero-days (CVE-2026-88771 and CVE-2026-88772), which forced some customers to pull the plug. The timing is particularly concerning, as it suggests that attackers are rapidly exploiting newly discovered vulnerabilities before patches can be applied.

Citrix has confirmed that the new vulnerability affects systems that were already patched against the previous two zero-days. This means that administrators may need to reapply patches or take other mitigating measures to protect their appliances. The company is urging customers to review their security configurations and apply any necessary updates as soon as possible.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address the vulnerability by October 7. This is the sixth exploited NetScaler vulnerability that CISA has added to its catalog in 2026.

The rapid succession of zero-day vulnerabilities affecting Citrix NetScaler appliances highlights the importance of maintaining up-to-date security configurations and applying patches promptly. Administrators should review their systems’ security settings, apply any necessary updates, and consider implementing additional mitigating measures to protect against these types of attacks.

In light of this latest development, we urge all Citrix administrators to take immediate action to secure their appliances. This includes reviewing system logs for signs of exploitation, applying any available patches or updates, and considering the use of additional security measures such as intrusion detection systems (IDS) or network segmentation. By taking proactive steps to protect against these types of attacks, organizations can minimize the risk of data breaches and maintain business continuity in the face of emerging threats.


Source: SecurityWeek — 2026-10-05