Citrix discloses third actively exploited NetScaler zero-day in less than a week
Citrix patched CVE-2026-88779, a third exploited NetScaler zero-day causing denial of service on SAML appliances.
Citrix disclosed CVE-2026-88779, its third actively exploited NetScaler zero-day in under two weeks, a high-severity denial-of-service flaw that affects only appliances with SAML enabled. CISA added it to the Known Exploited Vulnerabilities catalog, and watchTowr said exploitation likely began Friday and needs only a single crafted request. The bug is technically unrelated to the prior pair but can crash devices to speed exploitation of CVE-2026-88771. Researchers rate the impact lower than those earlier flaws, though attempts contain shellcode suggesting possible chaining toward remote code execution. Citrix has released a patch and urged customers to apply it quickly.
- CVE-2026-88779 is a NetScaler denial-of-service zero-day limited to SAML-enabled instances.
- CISA added the defect to its Known Exploited Vulnerabilities catalog Sunday.
- One crafted request can knock an appliance offline; exploitation likely began Friday.
- Crashing devices can accelerate exploitation of previously disclosed CVE-2026-88771.
- Observed attempts include shellcode, suggesting attackers may chain toward code execution.
Vulnerabilities mentionedAll →
- CVE-2026-887719.51%Unauthenticated RCE in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×4
Full article752 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days.
Citrix customers just got through back-to-back weekends filled with varying levels of uncertainty and worry, as yet another actively exploited zero-day vulnerability was discovered in Citrix NetScaler products.
Researchers and security experts said the vulnerability — CVE-2026-88779 — is less concerning because exploitation triggers denial of service and only impacts instances that have SAML (security assertion markup language) enabled.
“This means it doesn’t work out of the box against every NetScaler deployment,” Jake Knott, head of threat intelligence at watchTowr, told CyberScoop. “While this is very inconvenient, it doesn’t have organizations scrambling to trigger incident response.”
Citrix was much quicker and consistent in alerting customers to the emerging threat Friday, and followed up the next day with a more detailed blog post and security advisory that contained a patch for the high-severity defect.
“After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix,” a company spokesperson said in a statement. “The fix for this issue is available, and we urge all customers to quickly apply it to their NetScaler instance.”
The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Sunday.
The vendor’s response also provided some relief for customers and researchers who spent much of the previous weekend rushing to assess widespread rumors of other defects in the assailed network edge gateways. In that case, Citrix took most of the weekend to confirm attackers were actively exploiting a pair of NetScaler zero-days, some of which researchers said remained undetected for at least three weeks.
“Citrix did a better job with their response to this vulnerability,” and took steps that enabled customers to make their own risk-based decisions with more currently available information, said Joe Toomey, vice president of underwriting security at insurance provider Coalition.
“Although it’s difficult to celebrate given this is the third publicly-exploited NetScaler zero-day vulnerability in a two-week window, it is a step in the right direction,” he added.
Citrix declined to say how many customers are impacted by the latest zero-day or when the first instance of exploitation occurred. Yet, Knott at watchTowr said exploitation likely began Friday.
The newer defect doesn’t share any technical links with the pair of zero-days Citrix disclosed less than a week prior, but it can accelerate one of those vulnerabilities — CVE-2026-88771 — by intentionally crashing machines to speed up exploitation, Knott said.
While risk is currently perceived low for CVE-2026-88779, it is “incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” Knott added. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.”
Toomey also described the denial-of-service vulnerability as less serious than the previous week’s actively exploited zero-days. Yet, he noted, exploitation attempts of CVE-2026-88779 “clearly contain shellcode that implies that the threat actor believes they can use this vulnerability, or chain it with another vulnerability, in order to achieve remote-code execution.”
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
Technology
Threats
WaterISAC reckons with range of threats after summer of cyberattacks
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Alleged ShinyHunters leader arrested in the Netherlands
Kiteworks lifts shutdown advisory after 'credible threat intelligence' from federal authorities
Policy
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The president has called for AI leadership. Here’s the mission.