Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix NetScaler zero-day CVE-2026-88779 is exploited in the wild against patched appliances, causing DoS with possible RCE; CISA added it to KEV.
Citrix confirmed CVE-2026-88779, a memory overflow affecting NetScaler ADC and Gateway configured as SAML SP or IdP, is being exploited in targeted attacks causing denial of service, with indications it may also enable remote code execution. Admin logs showed authentication requests with shell commands hidden in the username field fetching a script that plants web shells, persists across reboots, and uploads appliance configurations and backups; Kevin Beaumont observed exploitation attempts against patched honeypots, one downloading a malware binary. CISA added the CVE to its KEV catalog on October 4 with an October 7 federal deadline, the sixth exploited NetScaler vulnerability added in 2026. The bug follows actively exploited zero-days CVE-2026-88771 and CVE-2026-88772 (PitScaler), which had forced some customers to disconnect appliances.
- CVE-2026-88779 memory overflow hits NetScaler ADC/Gateway in SAML SP or IdP roles
- Exploited in the wild on already-patched appliances; primarily DoS, possible RCE
- Payload hides shell commands in username field to fetch script planting web shells
- CISA KEV addition October 4 with October 7 deadline; sixth exploited NetScaler CVE in 2026
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article390 words · extracted from securityweek.com · click to collapse
Citrix NetScaler administrators scrambled over the weekend to protect their appliances after exploitation of a new zero-day vulnerability began.
Administrators initially reported reboots of fully patched NetScaler systems on Friday, and Citrix soon confirmed the existence of another zero-day exploited in the wild.
According to Citrix, the new vulnerability, tracked as CVE-2026-88779 and classified as high severity, is a memory overflow issue affecting NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP.
“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix explained in a blog post. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”
The attacks were spotted just days after NetScaler administrators were warned about two actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772, which forced some customers to pull the plug.
While Citrix describes CVE-2026-88779 as a DoS vulnerability, there is some indication it may also be exploitable for remote code execution.
Advertisement. Scroll to continue reading.
Security researcher Kevin Beaumont, who dubbed the vulnerability PitScaler 2 (CVE-2026-88771 and CVE-2026-88772 are dubbed PitScaler), confirmed seeing exploitation attempts against patched honeypot instances. Beaumont also reported that one of his honeypots was running a downloaded malware binary.
Reddit users initially reported that NetScaler appliances already updated to the latest version in response to the CVE-2026-88771 and CVE-2026-88772 attacks kept rebooting. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field and meant to fetch and run a malicious script.
One user who obtained the script said it tries to plant web shells, survive reboots, and upload the appliance’s configuration and backups, but cautioned that there was no proof the script actually ran.
Before patches arrived, admins complained about support queues that lasted hours and about interim workarounds that sometimes failed to stop the crashes.
CISA added CVE-2026-88779 to its KEV catalog on October 4, instructing federal agencies to address it by October 7. This is the sixth exploited NetScaler vulnerability CISA added to its catalog in 2026.
Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild