Citrix NetScaler administrators rushed to respond after a new zero-day, CVE-2026-88779, was actively exploited against NetScaler ADC and NetScaler Gateway deployments configured as SAML SP or SAML IdP. Citrix and security researchers also linked the activity to prior exploited flaws and suspicious attack tooling that may have included malware delivery and attempts to plant web shells. #Citrix #NetScaler #CVE-2026-88779 #CVE-2026-88771 #CVE-2026-88772 #KevinBeaumont #CISA #PitScaler #PitScaler2
Keypoints
- CVE-2026-88779 is a high-severity memory overflow in Citrix NetScaler.
- The flaw affects NetScaler ADC and NetScaler Gateway in SAML configurations.
- Citrix observed targeted attacks causing denial of service on unmitigated systems.
- Researchers saw exploitation attempts against patched honeypots and a downloaded malware binary.
- CISA added CVE-2026-88779 to its KEV catalog with an October 7 deadline for federal agencies.