New Citrix NetScaler Zero-Day Hits Already-Patched Systems
Want more insights like this?
A fresh zero-day vulnerability is hitting Citrix NetScaler appliances — even ones administrators had just patched days earlier. Tracked as CVE-2026-88779, the high-severity memory overflow flaw affects NetScaler ADC and Gateway instances configured as SAML SP or IdP, causing Denial of Service through repeated crashes. Those earlier patches covered CVE-2026-88771 and CVE-2026-88772, fixed the week before.
Security researcher Kevin Beaumont, who named this one PitScaler 2, confirmed seeing exploitation attempts against patched honeypots, and reported one honeypot running a downloaded malware binary. Admins reported reboots alongside logs showing shell commands buried in username fields. One admin who retrieved the script said it tries to plant web shells, survive reboots and upload configuration and backups — while cautioning there was no proof it ever ran.
Security firm watchTowr has since reproduced the flaw and found it can only crash systems, with no route to code execution. The firm suspects attackers crashed machines deliberately to make exploitation of CVE-2026-88771 faster. Citrix says the same thing from its side: service availability is affected, customer data integrity is not.
CISA added the flaw to its KEV catalog on October 4, giving federal agencies until October 7 to remediate. It's the sixth exploited NetScaler vulnerability CISA has cataloged in 2026.
Source: SecurityWeek