Back to Feed
VulnerabilitiesOct 5, 2026

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix NetScaler zero-day CVE-2026-88779 exploited in the wild shortly after patches for other flaws.

Summary

Citrix has confirmed exploitation of a new zero-day vulnerability, CVE-2026-88779, affecting NetScaler ADC and Gateway instances. This high-severity memory overflow issue, dubbed PitScaler 2, emerged just days after patches for two other actively exploited zero-days were released. While initially reported as a Denial of Service (DoS) vulnerability, there are indications it may also allow for remote code execution, with observed attacks attempting to plant web shells and exfiltrate data.

Full text

Citrix NetScaler administrators scrambled over the weekend to protect their appliances after exploitation of a new zero-day vulnerability began. Administrators initially reported reboots of fully patched NetScaler systems on Friday, and Citrix soon confirmed the existence of another zero-day exploited in the wild. According to Citrix, the new vulnerability, tracked as CVE-2026-88779 and classified as high severity, is a memory overflow issue affecting NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP. “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix explained in a blog post. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.” The attacks were spotted just days after NetScaler administrators were warned about two actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772, which forced some customers to pull the plug. While Citrix describes CVE-2026-88779 as a DoS vulnerability, there is some indication it may also be exploitable for remote code execution. Advertisement. Scroll to continue reading. Security researcher Kevin Beaumont, who dubbed the vulnerability PitScaler 2 (CVE-2026-88771 and CVE-2026-88772 are dubbed PitScaler), confirmed seeing exploitation attempts against patched honeypot instances. Beaumont also reported that one of his honeypots was running a downloaded malware binary. Reddit users initially reported that NetScaler appliances already updated to the latest version in response to the CVE-2026-88771 and CVE-2026-88772 attacks kept rebooting. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field and meant to fetch and run a malicious script. One user who obtained the script said it tries to plant web shells, survive reboots, and upload the appliance’s configuration and backups, but cautioned that there was no proof the script actually ran. Before patches arrived, admins complained about support queues that lasted hours and about interim workarounds that sometimes failed to stop the crashes. CISA added CVE-2026-88779 to its KEV catalog on October 4, instructing federal agencies to address it by October 7. This is the sixth exploited NetScaler vulnerability CISA added to its catalog in 2026. Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs AI Agents Aimed SQL Injection at US and Canadian Government SitesPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Latest News Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Forcedoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet MisadventuresFortra Patches Critical Vulnerabilities in BoKSIn Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI ChatsmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoorCrypto Scammers Hijack Microsoft’s Official X AccountIn Rare Move, Alleged Iranian State Hacker Extradited to USWarlock Expands SharePoint Exploitation in Critical Infrastructure Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-88779
  • cve — CVE-2026-88771
  • cve — CVE-2026-88772

Entities

NetScaler ADC (product)NetScaler Gateway (product)Citrix (vendor)SAML (technology)web shells (technology)