Network Security, Vulnerability Management, Patch/Configuration Management

New Citrix Netscaler zero-day exploited just days after recent attacks

Citrix sign on its office building in Fort Lauderdale, Florida, USA, an American cloud computing and virtualization technology company.

A few days after the Google Threat Intelligence Group (GTIG) reported that two novel forms of malware were actively exploiting Citrix NetScaler ADC and NetScaler Gateway appliances, Citrix stated that a new zero-day was exploiting the very same ADC and Gateway NetScaler systems.

The high-severity CVSS 8.7 bug — CVE-2026-88779 — was added to the known exploited vulnerabilities (KEV) catalog over the weekend by the Cybersecurity and Infrastructure Security Agency (CISA), which described it as a memory buffer vulnerability.

In a blog post over the weekend, Citrix confirmed that it observed targeted attacks on unmitigated NetScaler deployments that can lead to a denial-of-service (DoS) attack.

“If the condition is triggered repeatedly, the service may remain unavailable,” wrote the Citrix researchers. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data. Citrix strongly urges all customers to install the latest versions as soon as possible.” 

Roman Sannikov, global research coordinator at iCounter, said that three exploited NetScaler vulnerabilities in roughly a week shows attackers are focused on this product line and moving as fast as Citrix can ship fixes. Sannikov said CVE-2026-88779 hit appliances that were just patched for CVE-2026-88771 and CVE-2026-88772.

“When the next exploitable flaw shows up days after a patch, it usually means a capable actor has been studying the platform closely,” said Sannikov. “Researchers still disagree on how serious this one is. watchTowr assesses it as a DoS bug, while [cybersecurity personality] Kevin Beaumont observed malware being downloaded onto patched honeypots after exploitation attempts.”

Sannikov said threat actors appear to be chaining the vulnerabilities, likely using the latest DoS flaw to mask their attempts to use the earlier vulnerabilities to gain remote access. Defenders should treat it as more than a crash risk: it only affects ADC and Gateway instances configured as a SAML service provider or identity provider, so the first step is knowing which of the company’s appliances are set up that way.

“Then patch, review activity on those devices over the past several weeks, and look into unexpected reboots, which were among the reported signs of exploitation,” said Sannikov.

Jake Knott, watchTowr's head of threat intelligence, said this vulnerability is incredibly simple to trigger, with a single specially crafted request being all that an attacker needs to knock an appliance offline. Exploitation has already been occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it, said Knott.

"CVE-2026-88779 is a DoS vulnerability in Citrix NetScaler that lets an unauthenticated, external attacker perform a memory overflow and force it offline," said Knott. "The vulnerability specifically affects appliances configured as a SAML service provider or identity provider, both of which are commonly used by enterprises to support single sign-on authentication."

Seemant Sehgal, chief executive officer at BreachLock, added that fully patched appliances getting exploited again days after an emergency update signals that perimeter infrastructure has been operating on a threat timeline that most organizations have not restructured their security operations around.

“Patching is obviously necessary, but it’s not the control point it used to be when the window between disclosure and exploitation was measured in weeks instead of hours,” said Sehgal.

Sehgal said organizations that stay ahead of this treat every internet-facing appliance as presumed compromised when a critical CVE drops, isolate and investigate immediately rather than waiting for the patch cycle to catch up, and have a plan for operating without that device if the investigation turns up something worth acting on. Sehgal said the teams that handle these best are the ones running continuous penetration testing against their external attack surface, so when a zero-day lands they already know how an attacker would move and are deciding what to shut down rather than figuring out what they have.

Andi Ursry, threat intelligence analyst at Blackpoint, said along with patching, organizations with impacted configurations should check the appliance and surrounding environment for signs of compromise, credential theft, persistence, or anything suggesting an attacker used the device as a foothold into the network.

“For teams that patched NetScaler last week, it’s frustrating having to turn around and do it again,” said Ursry. “But NetScaler's exposure, its function, and its history of being targeted mean it stays near the top of the list, especially with exploitation already active.”

Shane Barney, chief information security officer at Keeper Security, pointed out that threat actors don’t need to invent new attack vectors when they can exploit existing ones more efficiently. Barney explained that chaining vulnerabilities together using a memory overflow DoS bug like CVE-2026-88779 to purposefully crash systems and force reboots was a tactical move designed to accelerate the exploitation of secondary flaws like CVE-2026-88771.

“It reflects an adversary landscape focused on speed, efficiency and taking the path of least resistance,” said Barney. “For security teams, these rapid-fire zero-day disclosures on perimeter appliances like NetScaler ADC and Gateway highlight the inherent risk of reliance on perimeter defenses alone. When edge devices, especially those handling SAML authentication, are compromised or forced offline, the blast-radius can widen rapidly if internal controls are not tightly governed.”

Tomer Filiba, chief technology officer of Sweet Security, added that three exploited NetScaler zero-days in a matter of weeks tells us the edge will keep losing.

“Patch today, then hunt the box itself,” said Filiba. “Researchers are already finding malware on appliances that were patched. And assume someone got through. The place you can still stop them is behind the gateway, in the systems they're trying to reach."

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.
Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds