Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix NetScaler Appliances Hit by New Zero-Day Vulnerability in Quick Succession

A fresh wave of attacks is hitting Citrix NetScaler appliances, just days after administrators were warned about two actively exploited zero-day vulnerabilities. The latest exploit, tracked as CVE-2026-88779, has been identified as a high-severity memory overflow issue that can cause denial-of-service (DoS) and potentially even remote code execution.

The vulnerability affects NetScaler ADC and Gateway instances configured as SAML Service Provider (SP) or Identity Provider (IdP), making it vulnerable to exploitation. Citrix confirmed the existence of the zero-day after administrators reported reboots of fully patched systems on Friday, prompting a swift response from the company.

In its official blog post, Citrix noted that targeted attacks have been observed against unmitigated NetScaler deployments, which can lead to DoS and service unavailability. While there is no indication that customer data has been compromised, analysts are concerned about the potential for remote code execution, which could grant attackers access to sensitive information.

This latest exploit comes on the heels of two previously disclosed zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which were also targeted by malicious actors. The swift succession of these attacks has left some NetScaler administrators scrambling to protect their appliances, with support queues and workarounds proving ineffective in stopping the crashes.

Security researchers have been tracking the exploits, with Kevin Beaumont confirming that he saw exploitation attempts against patched honeypot instances. One user who obtained a malicious script reported that it tries to plant web shells, survive reboots, and upload configuration and backups – although there is no conclusive evidence that the script actually ran.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, instructing federal agencies to address the issue by October 7. This marks the sixth exploited NetScaler vulnerability CISA has added to its catalog this year, highlighting the ongoing challenges faced by administrators in keeping these systems secure.

As a practical takeaway for NetScaler administrators, it’s essential to stay vigilant and monitor their appliances closely for signs of exploitation. Regularly reviewing system logs, patching vulnerabilities promptly, and implementing robust security measures can help prevent these types of attacks. Additionally, administrators should be aware of the potential for social engineering tactics, such as hidden shell commands in authentication requests, which can aid malicious actors in gaining access to sensitive systems.


Source: SecurityWeek — 2026-10-05