Skip to main content
Emerging Threats

Citrix Unveils Third Exploited NetScaler Zero-Day Vulnerability

Rows of computer equipment and networking gear in a large server room with IT staff walking between rows.

CVE-2026-88779 is the third actively exploited NetScaler zero-day vulnerability disclosed in less than a week — and unlike the earlier pair, exploitation of this defect results in denial of service and only affects NetScaler instances that have SAML enabled.

CVE-2026-88779: denial of service limited to SAML-enabled deployments

Security researchers characterized CVE-2026-88779 as a high-severity defect whose exploitation causes an appliance to crash. Jake Knott, head of threat intelligence at watchTowr, told CyberScoop that the vulnerability “doesn’t work out of the box against every NetScaler deployment” because it only impacts instances with SAML (security assertion markup language) enabled. Knott added the flaw is “incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline.”

Researchers emphasized that while the immediate effect is denial of service — disrupting an authentication gateway and preventing legitimate users from reaching services behind it — exploitation is “already occurring in the wild,” according to reporting in CyberScoop.

Citrix’s communications and patching timeline

Citrix alerted customers Friday about the new defect and followed up the next day with a blog post and a security advisory that included a patch. In a written statement quoted by CyberScoop, a Citrix spokesperson said: “After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix. The fix for this issue is available, and we urge all customers to quickly apply it to their NetScaler instance.”

Observers in the security community said Citrix’s handling of this disclosure was faster and more consistent than its response to the earlier pair of zero-days disclosed the prior weekend.

CISA inclusion, timing questions, and earlier NetScaler disclosures

The Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its known exploited vulnerabilities catalog on Sunday. Citrix declined to provide figures for how many customers are impacted or to confirm when the first exploitation occurred; Jake Knott said exploitation likely began Friday.

The new advisory brought some relief after a prior weekend in which Citrix “took most of the weekend to confirm attackers were actively exploiting a pair of NetScaler zero-days,” some of which researchers said remained undetected for at least three weeks. That earlier episode and the current disclosure together amount to three publicly exploited NetScaler zero-days within a two-week window, a cadence that security professionals and insurers described with concern.

Linkages to CVE-2026-88771 and evidence of threat-actor intent

Although CVE-2026-88779 “doesn’t share any technical links” with the pair of zero-days disclosed less than a week prior, researchers told CyberScoop the new defect can accelerate exploitation of one of those earlier flaws — CVE-2026-88771 — by intentionally crashing machines to speed up follow-on attacks. Joe Toomey, vice president of underwriting security at insurance provider Coalition, said the denial-of-service nature of CVE-2026-88779 makes it “less serious than the previous week’s actively exploited zero-days.”

Yet Toomey also warned that exploitation attempts against CVE-2026-88779 “clearly contain shellcode that implies that the threat actor believes they can use this vulnerability, or chain it with another vulnerability, in order to achieve remote-code execution.” That observation underscores why researchers view an apparently simple denial-of-service defect as a potential enabler for more severe outcomes when used in combination with other bugs.

What this means for security teams, insurers, and administrators

  • Security teams and administrators: apply the vendor-provided mitigation and the available fix without delay, and prioritize assessment of NetScaler appliances with SAML enabled, since those are the only deployments the advisory says are directly affected.
  • Insurance and underwriting teams: monitor exploit artifacts and vendor communications; Coalition’s underwriting-security leadership publicly noted the improved vendor response but stressed the seriousness of a third NetScaler zero-day in two weeks.
  • Enterprise IT and access-management owners: watch for disruption to authentication gateways, since researchers warned that crashing an appliance “can prevent legitimate users from accessing the services behind it,” and evaluate whether CVE-2026-88779 could be used to accelerate exploitation of previously disclosed flaws such as CVE-2026-88771.

Citrix’s faster, clearer advisory this time and an available fix provide administrators with actionable steps. Still, key questions remain in the record presented by the vendor and researchers: how many customers were affected, and when exploitation began in earnest. With multiple NetScaler zero-days disclosed publicly within a short interval, the visible facts — straightforward exploitability, signs of shellcode in attack attempts, and the ability to chain a denial-of-service into a more serious compromise — leave defenders and insurers watching urgent patching and incident telemetry for the next signs of active exploitation.

Source: CyberScoop