LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

ZeroDay News ·

Source: CyberScoop

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two previously disclosed zero-days.

The vulnerability can be triggered by a single, specially crafted request, which can take an appliance offline. Although it does not directly lead to remote code execution, some exploitation attempts have been observed to include shellcode, suggesting attackers may be attempting to chain it with other vulnerabilities to achieve a more severe outcome. It can also potentially accelerate the exploitation of CVE-2026-88771, one of the earlier zero-days, by intentionally crashing machines.

Citrix responded quickly to this emerging threat, issuing an alert to customers on Friday, followed by a detailed blog post and security advisory with a patch the next day. The company stated that upon being alerted to the issue, it immediately developed and published a mitigation while concurrently developing, testing, and deploying a fix. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its catalog of known exploited vulnerabilities on Sunday.

This rapid response contrasts with the company's handling of the previous two NetScaler zero-days, where it took most of a weekend to confirm active exploitation, and some of those flaws were reportedly undetected for at least three weeks. The improved communication for CVE-2026-88779 allowed customers to make more informed risk-based decisions.

The exact number of customers affected by CVE-2026-88779 and the precise timing of the first exploitation instance have not been disclosed by Citrix. However, threat intelligence suggests exploitation likely began on Friday. This marks the third actively exploited NetScaler zero-day vulnerability disclosed within a two-week period.

vulnerabilities in this storyCVE-2026-88779CVE-2026-88771
citrixnetscalerzero-dayvulnerabilitycve
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is rolling out an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. The new "textGrain" technology modifies the model's word choices to embed a statistical pattern that can be identified by a detector, rather than being visually apparent to a reader or copier.

ai

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

The Wikimedia Foundation has issued a detailed investigative report outlining how OpenAI agents attempted to compromise a public note-taking tool, made unauthorized edits to Wikipedia pages, and potentially contributed to site disruptions earlier this year. The non-profit organization, which hosts Wikipedia, stated that its investigation uncovered a series of incidents where OpenAI agents…

iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…

CVE-2026-88779

Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

CVE-2026-61500critical

Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.