Skip to content
Cybersecurity

Citrix NetScaler Zero-Day Exploited Days After Emergency Patches

Citrix NetScaler zero-day CVE-2026-88779 exploited in the wild

New NetScaler Zero-Day Under Attack

Citrix NetScaler administrators are facing another security emergency after attackers began exploiting a newly disclosed zero-day vulnerability just days after the company released patches for two other actively exploited flaws.

Tracked as CVE-2026-88779, the new vulnerability is a high-severity memory-overflow issue affecting NetScaler ADC and NetScaler Gateway appliances configured as a SAML service provider or SAML identity provider. Citrix says it has observed targeted attacks against unmitigated deployments.

Citrix currently describes the vulnerability primarily as a denial-of-service issue. However, security researcher Kevin Beaumont reported seeing exploitation attempts against patched honeypots, while other observations suggest attackers may be attempting to achieve deeper access.

Attackers Target Even Recently Patched Appliances

The timing is particularly concerning because the new attacks emerged shortly after administrators rushed to patch CVE-2026-88771 and CVE-2026-88772, two critical NetScaler zero-days that Citrix confirmed were already being exploited.

Those earlier vulnerabilities could enable unauthenticated remote code execution, prompting Citrix and CISA to issue urgent warnings. Security researchers subsequently observed attacks against organisations in government, financial services, technology, education and professional services.

Administrators who installed the earlier emergency updates may therefore need to perform another upgrade if their systems meet the conditions for CVE-2026-88779.

SAML Configuration Determines Exposure

CVE-2026-88779 does not affect every NetScaler deployment. The vulnerability requires the appliance to be configured for SAML authentication, either as a SAML service provider or identity provider.

Citrix says affected NetScaler ADC and Gateway versions include 14.1 builds before 14.1-73.41 and 13.1 builds before 13.1-64.28, alongside corresponding FIPS and NDcPP versions. Customers have been advised to review their configurations and install the applicable fixed releases.

Citrix says its current analysis has not identified an impact on customer data integrity and characterises the observed attacks as potentially causing repeated service disruption. Security researchers, however, are continuing to investigate the behaviour seen in the wild.

CISA Adds the Flaw to KEV

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) Catalog on October 4. Federal agencies have been given until October 7 to address the vulnerability.

This is the sixth exploited NetScaler vulnerability added to the KEV catalog during 2026, according to SecurityWeek. The repeated exploitation of the platform has put additional pressure on organisations using NetScaler appliances as externally accessible gateways.

Another Patch Cycle for NetScaler Customers

The latest incident shows why internet-facing network appliances remain attractive targets even after emergency patches are deployed. Attackers can move quickly from one vulnerability to another, while organisations may need additional time to test and roll out replacement builds across production environments.

For affected customers, Citrix recommends upgrading to the fixed releases. A temporary Global Deny List mitigation is also available for certain already-patched versions, but Citrix continues to recommend upgrading where possible.

The immediate priority is therefore not only applying the latest patch but also checking whether systems were targeted during the earlier NetScaler attacks. Security teams should review logs and other indicators of compromise alongside the new upgrade cycle rather than assuming that a previous patch completely closed the exposure.