LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

ZeroDay News ·

Source: BleepingComputer

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

The vulnerability carries a CVSS score of 8.7 and impacts appliances configured for SAML authentication, either as a SAML Service Provider (SP) or a SAML Identity Provider (IdP). Citrix confirmed that these attacks have caused service unavailability but stated that there is no identified impact on the integrity of customer data.

Emergency updates were released early Sunday morning, October 4, 2026, with versions 14.1-73.41 and 13.1-64.28 addressing the flaw. FIPS deployments require specific upgrades: 14.1-73.41 FIPS for general FIPS customers and 13.1-37.282 for NetScaler ADC FIPS and NDcPP customers on the 13.1 branch. Citrix also provides Global Deny Lists to block known malicious IP addresses, though immediate installation of the security updates is strongly recommended.

This new vulnerability requires a further upgrade for organizations that recently patched their NetScaler devices against two previously exploited flaws. Citrix explicitly warned customers who upgraded for CVE-2026-88771 through CVE-2026-88778 to upgrade again if their deployments meet the SAML configuration preconditions.

While Citrix initially characterized CVE-2026-88779 as a denial-of-service vulnerability, cybersecurity researchers and NetScaler administrators have observed activity suggesting potential for remote code execution. Reports surfaced on Thursday from administrators noting unexpected reboots of recently patched NetScaler appliances, including those running version 14.1-73.37. These incidents involved repeated crashes of the `nsaaad` process, leading to appliance reboots when NetScaler's Pitboss process reached its restart limit.

One administrator investigating these crashes on a NetScaler 14.1-73.37 device found crafted authentication usernames containing shell commands. These commands attempted to download a payload from the IP address 213.209.159[.]55, save it as `/v`, and execute the file. These requests immediately preceded confirmed `nsaaad` crash sequences and targeted multiple SAML authentication factors. While the logs showed attempted exploitation and correlated crashes, successful command execution was not definitively confirmed in this instance.

A cybersecurity expert also reported that patched NetScaler 13.1 and 14.1 honeypots were crashing due to requests from various source IP addresses. Further investigation revealed that one of these patched honeypots was running a downloaded malware payload, indicating that the activity extended beyond denial-of-service. The expert noted that CVE-2026-88779, like the earlier CVE-2025-6543, was initially described as a memory overflow leading to denial-of-service before later attacks demonstrated remote code execution capabilities.

Another cybersecurity firm confirmed successful reproduction of the vulnerability after investigating reports of NetScaler honeypot activity, though technical details have not yet been released. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and mandating mitigation for federal civilian executive branch (FCEB) agencies by October 7.

vulnerabilities in this storyCVE-2026-88779
vulnerabilityzero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.