Citrix discloses third actively exploited NetScaler zero-day in less than a week

Citrix discloses third actively exploited NetScaler zero-day in less than a week
Citrix disclosed CVE-2026-88779, an actively exploited NetScaler zero-day that primarily causes denial of service and only affects deployments with SAML enabled. Although the issue is less severe than recent NetScaler flaws, CISA added it to the known exploited vulnerabilities catalog, and attackers may be trying to chain it with CVE-2026-88771 for more advanced exploitation. #Citrix #NetScaler #CVE-2026-88779 #CVE-2026-88771 #CISA

Keypoints

  • Citrix disclosed a new actively exploited NetScaler zero-day, CVE-2026-88779.
  • The flaw mainly triggers denial of service and affects only SAML-enabled instances.
  • Citrix released a mitigation and patch quickly after learning of the issue.
  • CISA added CVE-2026-88779 to its known exploited vulnerabilities catalog.
  • Researchers warned attackers may try to chain the flaw with CVE-2026-88771 for remote-code execution.

Read More: https://cyberscoop.com/citrix-netscaler-third-exploited-zero-day-vulnerability/