Over the weekend, administrators managing Citrix NetScaler systems were on high alert as a new zero-day vulnerability started being exploited. This security flaw, identified as CVE-2026-88779, poses a significant threat to NetScaler appliances, compelling administrators to take swift action to safeguard their systems.
Immediate Response to Emerging Threat
On Friday, reports surfaced of unexpected reboots in fully patched NetScaler systems. Citrix quickly verified that a new zero-day vulnerability was being actively exploited. This vulnerability, categorized as high severity, involves a memory overflow issue affecting NetScaler ADC and Gateway configured as SAML SP or IdP.
In a detailed blog post, Citrix highlighted targeted attacks on vulnerable NetScaler deployments. These could result in Denial of Service (DoS) situations, potentially leaving the service inaccessible if the condition is repeatedly triggered. However, Citrix noted that the integrity of customer data remains unaffected.
Recent Vulnerabilities and Exploitation Attempts
The discovery of CVE-2026-88779 follows closely after warnings about two other zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772. These earlier threats prompted some NetScaler customers to temporarily shut down their systems.
Security expert Kevin Beaumont, who named these vulnerabilities PitScaler 2, observed exploitation attempts on patched honeypot instances. Beaumont reported that one honeypot was compromised with a malware binary, indicating the potential for remote code execution beyond just a DoS attack.
Community and Agency Reactions
Reports on Reddit revealed that even after applying the latest updates, some NetScaler appliances continued to reboot. Affected administrators found logs with authentication requests that included shell commands, suggesting attempts to retrieve and execute harmful scripts.
A script linked to these attacks aims to install web shells, persist through reboots, and upload configurations and backups of the appliances. However, there is no concrete evidence that the script executes successfully.
Before patches were released, administrators faced long support queues and tried interim solutions that often failed. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 4, setting a deadline of October 7 for federal agencies to address it.
This incident marks the sixth NetScaler vulnerability added to CISA’s catalog in 2026, emphasizing the ongoing challenges in securing critical infrastructure.
