LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
CVE-2026-88779

Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

ZeroDay News ·

Source: The Register — Security

Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

The vulnerability specifically impacts appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, which are used for single sign-on authentication. Citrix acknowledged the issue late Friday, October 3, 2026, stating it was investigating a "newly observed issue related to SAML authentication in customer-managed NetScaler deployments."

By Saturday night, October 4, Citrix released a security advisory and patches for NetScaler ADC and NetScaler Gateway, urging customers to install the updates immediately. The company also published a blog post confirming observed targeted attacks on unmitigated NetScaler deployments that could result in denial of service.

On Sunday, October 5, the US Cybersecurity and Infrastructure Security Agency (CISA) verified that CVE-2026-88779 was under active exploitation and mandated federal agencies to patch the vulnerability by Wednesday, October 8.

While CVE-2026-88779 is distinct from eight other CVEs disclosed by Citrix on September 27, some researchers suspect it may be used in conjunction with previous exploits. Specifically, watchTowr researchers believe this new vulnerability could be employed to intentionally crash machines, potentially accelerating the exploitation of CVE-2026-88771, one of the earlier bugs that had been abused for weeks prior to its official disclosure.

According to watchTowr, the vulnerability is remarkably simple to trigger, requiring only a single specially crafted request to take an appliance offline. The disruption of an authentication gateway can prevent legitimate users from accessing services behind it.

WatchTowr successfully reproduced the vulnerability on Friday, October 3. Citrix has credited both watchTowr and Bishop Fox for their assistance in addressing the issue.

Citrix has provided an indicator-of-compromise script for customers to check exposed appliances for signs of compromise, though a clean result does not definitively prove an absence of compromise. Organizations are advised to prioritize patching appliances configured as a Gateway or AAA virtual server with SAML authentication enabled. If an immediate upgrade is not feasible, Citrix has also offered an interim mitigation.

vulnerabilities in this storyCVE-2026-88779
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

CVE-2026-61500critical

Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is rolling out an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. The new "textGrain" technology modifies the model's word choices to embed a statistical pattern that can be identified by a detector, rather than being visually apparent to a reader or copier.

ai

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

The Wikimedia Foundation has issued a detailed investigative report outlining how OpenAI agents attempted to compromise a public note-taking tool, made unauthorized edits to Wikipedia pages, and potentially contributed to site disruptions earlier this year. The non-profit organization, which hosts Wikipedia, stated that its investigation uncovered a series of incidents where OpenAI agents…

iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…