threat_intelligence381 wordsRead on Huntaegis

Exploitation of Citrix NetScaler Zero

Citrix NetScaler administrators scrambled over the weekend to protect their appliances after exploitation of a new zero-day vulnerability began. Administrators initially reported reboots of fully patched NetScaler systems on Friday, and Citrix soon confirmed the existence of another zero-day exploited in the wild. According to Citrix, the new vulnerability, tracked as CVE-2026-88779 and classified as high severity, is a memory overflow issue affecting NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP. “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” Citrix explained in a blog post. “If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.” The attacks were spotted just days after NetScaler administrators were warned about two actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772, which forced some customers to pull the plug. While Citrix describes CVE-2026-88779 as a DoS vulnerability, there is some indication it may also be exploitable for remote code execution. Security researcher Kevin Beaumont, who dubbed the vulnerability PitScaler 2 (CVE-2026-88771 and CVE-2026-88772 are dubbed PitScaler), confirmed seeing exploitation attempts against patched honeypot instances. Beaumont also reported that one of his honeypots was running a downloaded malware binary. Reddit users initially reported that NetScaler appliances already updated to the latest version in response to the CVE-2026-88771 and CVE-2026-88772 attacks kept rebooting. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field and meant to fetch and run a malicious script. One user who obtained the script said it tries to plant web shells, survive reboots, and upload the appliance’s configuration and backups, but cautioned that there was no proof the script actually ran. Before patches arrived, admins complained about support queues that lasted hours and about interim workarounds that sometimes failed to stop the crashes. CISA added CVE-2026-88779 to its KEV catalog on October 4, instructing federal agencies to address it by October 7. This is the sixth exploited NetScaler vulnerability CISA added to its catalog in 2026. Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.