BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Citrix NetScaler Zero-Day Exploited in Targeted Attacks

Citrix patches critical NetScaler memory overflow zero-day exploited in targeted attacks, CISA mandates fix.

  • Citrix released security updates for CVE-2026-88779, a high-severity memory overflow flaw in NetScaler ADC and Gateway exploited in targeted zero-day attacks.
  • The vulnerability (CVSS 8.7) affects customer-managed deployments configured as SAML service providers or identity providers, potentially enabling denial-of-service.
  • Patch versions include NetScaler ADC/Gateway 14.1-73.41 and 13.1-64.28; the U.S. CISA added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal fixes by October 7, 2026.
  • Researchers from Bishop Fox and watchTowr reported the flaw; watchTowr reproduced it within hours of detecting honeypot activity.

Citrix released security updates for a high-severity memory overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway that threat actors have exploited in targeted zero-day attacks. Tracked as CVE-2026-88779, the flaw carries a CVSS score of 8.7 out of 10.0.

- Advertisement -

The issue affects customer-managed NetScaler deployments running supported versions when configured either as a SAML service provider (SP) or SAML identity provider (IdP). According to Citrix, “CVE-2026-88779 is a memory overflow vulnerability … that can lead to denial-of-service under specific deployment conditions.”

Consequently, Citrix acknowledged targeted attacks on unmitigated deployments. The company stated, “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.” The patches address the flaw in NetScaler ADC and Gateway versions 14.1-73.41 and 13.1-64.28, along with FIPS variants.

The development follows reports of active exploitation of two other vulnerabilities, CVE-2026-88771 and CVE-2026-88772, used to plant web shells and tunneling tools. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by October 7, 2026.

Citrix credited Bishop Fox and watchTowr for reporting the flaw. In a post on X, watchTowr said it reproduced the security flaw within hours of detecting NetScaler honeypot activity.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US debt crisis slowly squeezes budget as interest hits $1.1T

The US debt crisis may be unfolding as a slow squeeze, with servicing costs...

Zcash’s NU7 live on testnet as November mainnet nears target

ZCash activated NU7 upgrade on testnet on October 4 at block 4,465,026.NU7 aims to...

Community banks sue OCC over crypto charters

The Independent Community Bankers of America sued the OCC in D.C. federal court, challenging...

Cathie Wood: Gold to Decline as Bitcoin, AI Cut Inflation

Cathie Wood expects further Gold declines as ARK's innovation themes like blockchain and AI...

Russian Finance Ministry pays staff wages in digital rubles for first time

The Ministry of Finance paid some employees in digital rubles for the first time...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading