<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

New Citrix NetScaler Zero-Day Hits Already-Patched Systems

Exploit targets Citrix NetScaler's new zero-day flaw, CVE-2026-88779, causing repeated crashes. Agencies urged to patch.
Content Team

A fresh zero-day vulnerability is hitting Citrix NetScaler appliances — even ones administrators had just patched days earlier. Tracked as CVE-2026-88779, the high-severity memory overflow flaw affects NetScaler ADC and Gateway instances configured as SAML SP or IdP, causing Denial of Service through repeated crashes. Those earlier patches covered CVE-2026-88771 and CVE-2026-88772, fixed the week before.

Security researcher Kevin Beaumont, who named this one PitScaler 2, confirmed seeing exploitation attempts against patched honeypots, and reported one honeypot running a downloaded malware binary. Admins reported reboots alongside logs showing shell commands buried in username fields. One admin who retrieved the script said it tries to plant web shells, survive reboots and upload configuration and backups — while cautioning there was no proof it ever ran.

Security firm watchTowr has since reproduced the flaw and found it can only crash systems, with no route to code execution. The firm suspects attackers crashed machines deliberately to make exploitation of CVE-2026-88771 faster. Citrix says the same thing from its side: service availability is affected, customer data integrity is not.

CISA added the flaw to its KEV catalog on October 4, giving federal agencies until October 7 to remediate. It's the sixth exploited NetScaler vulnerability CISA has cataloged in 2026.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo