Skip to main content
Emerging ThreatsMalware & Ransomware

Citrix NetScaler Exploited in Active Attacks Amid New 0-Day Reports

Rack-mounted Citrix NetScaler appliance with status lights and LCD display in a network operations room.

"We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson told The Register.

CVE-2026-88779: a SAML-related memory overflow that causes denial of service

Security researchers and the vendor say CVE-2026-88779 is a memory overflow vulnerability that can lead to denial of service (DoS) on Citrix NetScaler appliances. It affects NetScaler ADC and NetScaler Gateway instances that are configured as a SAML service provider or identity provider for single sign‑on authentication. WatchTowr reproduced the issue on Friday and described it as “incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline.”

Evidence of active exploitation and patch availability

Citrix confirmed late Friday that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night the company released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog confirming it had observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service.

Citrix told The Register it “immediately developed and published a mitigation while concurrently developing, testing and deploying a fix.” The vendor provided an indicator‑of‑compromise (IOC) script teams can run to check exposed appliances, though watchTowr cautioned “a clean result is not definitive proof.” Citrix did not answer questions about how many instances have been affected or what attackers do after exploiting the bug.

CISA orders federal agencies to patch; timeline and context

On Sunday the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. The new flaw is not technically related to a set of eight CVEs Citrix disclosed on September 27, but two of those earlier holes — CVE-2026-88772 and CVE-2026-88771 — had already been abused in the wild weeks before the vendor's disclosure.

Researcher findings: weaponizing crashes to speed other exploits

WatchTowr's head of threat intelligence, Jake Knott, told The Register he suspects CVE-2026-88779 has been used to purposefully crash appliances, “making exploitation of CVE-2026-88771 faster.” He emphasized the operational impact: “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” Citrix credited watchTowr and Bishop Fox with helping it address the issue.

What this means for NetScaler administrators, federal agencies, and security researchers

  • NetScaler administrators: Prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled; apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible, and run Citrix’s IOC script while recognizing a clean result may not be definitive.
  • Federal agencies: Follow CISA’s order to patch by Wednesday and treat exposed NetScaler ADC and Gateway SAML configurations as high priority due to confirmed active exploitation.
  • Security researchers and incident responders: Monitor for targeted attacks that may combine CVE-2026-88779-driven crashes with exploitation of CVE-2026-88771 or related CVEs disclosed on September 27; corroborate IOC script findings with additional telemetry because Citrix warns a clean script run is not definitive proof of absence of compromise.

Citrix and outside researchers have provided fixes, mitigations, and detection scripts, but key questions remain unanswered in public reporting: how many NetScaler instances have been impacted and what post‑exploit activity, if any, is occurring on compromised appliances. For now the immediate, concrete step is clear — apply the vendor’s patches or mitigations quickly, especially where SAML authentication is in use — and watch for follow‑on activity that could leverage availability failures to accelerate other intrusions.

https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232