Citrix NetScaler Zero-Day Leaves Freshly Patched Appliances Exposed
Want more insights like this?
Citrix has pushed emergency patches for a zero-day vulnerability in NetScaler ADC and Gateway appliances that attackers are already exploiting. Tracked as CVE-2026-88779 with a CVSS 4.0 score of 8.7, the memory overflow flaw hits systems configured as SAML service providers or identity providers, triggering denial of service through repeated crashes. No credentials or user interaction are needed to exploit it — just network access, and attack complexity is low.
Citrix confirmed targeted attacks and says the impact is availability only, with no sign of data theft. Its CVSS vector agrees, rating confidentiality and integrity impact at none. But the question isn't closed. Administrators logged authentication requests carrying shell commands, Kevin Beaumont saw a malware binary running on a patched honeypot, and watchTowr reproduced the flaw within hours. Nobody has confirmed code execution, and nobody has ruled it out.
Either way, the clock is running. CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 4 and gave federal agencies until October 7 to fix it, with forensic triage required under BOD 26-04 to establish whether an appliance was hit before the patch went on. To find out if you're in scope, check the configuration for add authentication samlAction or add authentication samlIdPProfile — either entry meets the precondition.
Administrators who patched for the two earlier NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, must upgrade again. Go to 14.1-73.41 or 13.1-64.28 on the standard branches, 14.1-73.41 FIPS for FIPS appliances, or 13.1-37.282 for 13.1 FIPS and NDcPP. Citrix-managed cloud services are covered already. Global Deny Lists buy time; patching ends it.
Source: Cyber Security News