LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

ZeroDay News ·

A critical vulnerability, CVE-2026-88779, affecting Citrix NetScaler ADC and NetScaler Gateway appliances was actively exploited in the wild at least two days before its official publication date of October 4, 2026. This pre-disclosure exploitation meant there was no patch window for affected organizations.

The flaw is described as an improper restriction of operations within the bounds of a memory buffer, which could be leveraged by attackers to cause a denial-of-service condition. Citrix confirmed the active exploitation of this zero-day vulnerability and issued urgent security updates to address it.

The vulnerability was first listed as exploited in the European Union's EUVD catalogue on October 2, 2026. Subsequently, it was added to the U.S. federal CISA Known Exploited Vulnerabilities (KEV) catalog and VulnCheck KEV on October 4, 2026, the same day the CVE was officially published. The CISA KEV listing mandates U.S. federal agencies to apply mitigations by October 7, 2026.

Public exploitation evidence was reported as early as September 27, 2026, with 17 public reports collected from various sources by October 4, 2026. The vulnerability carries a high severity rating, though its CVSS score was not specified. Its Exploit Prediction Scoring System (EPSS) percentile is 18.2%, indicating a moderate likelihood of exploitation.

Organizations utilizing Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are strongly advised to apply the vendor's recommended security updates immediately to mitigate the risk of denial-of-service attacks.

vulnerabilities in this storyCVE-2026-88779
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.