Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two previously disclosed zero-days.
The vulnerability can be triggered by a single, specially crafted request, which can take an appliance offline. Although it does not directly lead to remote code execution, some exploitation attempts have been observed to include shellcode, suggesting attackers may be attempting to chain it with other vulnerabilities to achieve a more severe outcome. It can also potentially accelerate the exploitation of CVE-2026-88771, one of the earlier zero-days, by intentionally crashing machines.
Citrix responded quickly to this emerging threat, issuing an alert to customers on Friday, followed by a detailed blog post and security advisory with a patch the next day. The company stated that upon being alerted to the issue, it immediately developed and published a mitigation while concurrently developing, testing, and deploying a fix. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its catalog of known exploited vulnerabilities on Sunday.
This rapid response contrasts with the company's handling of the previous two NetScaler zero-days, where it took most of a weekend to confirm active exploitation, and some of those flaws were reportedly undetected for at least three weeks. The improved communication for CVE-2026-88779 allowed customers to make more informed risk-based decisions.
The exact number of customers affected by CVE-2026-88779 and the precise timing of the first exploitation instance have not been disclosed by Citrix. However, threat intelligence suggests exploitation likely began on Friday. This marks the third actively exploited NetScaler zero-day vulnerability disclosed within a two-week period.






