CITRIX has confirmed a fresh zero-day affecting NetScaler appliances, tracked as CVE-2026-88779, appearing only a few days after two previously exploited flaws were patched. The new memory overflow vulnerability targets NetScaler ADC and NetScaler Gateway instances configured as a SAML service provider or identity provider, and is classed as high severity.
Citrix says the issue can cause denial of service if triggered repeatedly, potentially leaving the service unavailable, though it has not identified any data integrity impact.
Security researchers and administrators report a string of active exploitation beginning over the weekend, just after warnings about two earlier flaws (CVE-2026-88771 and CVE-2026-88772, nicknamed PitScaler). Honeypots observed exploitation attempts against patched systems, with one instance allegedly downloading a malware binary via a shell command embedded in a username field.
Some users reported NetScaler reboots even on updated appliances, and analysts note that the attacker activity described includes attempts to plant web shells, survive reboots and exfiltrate configuration and backups, though there is no conclusive proof of such outcomes at scale.
Evidence and practical response: CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalogue, with guidance for federal agencies to mitigate by 7 October. While Citrix describes the vulnerability primarily as DoS, there are indications of potential remote code execution. Administrators are urged to apply the fixes released for the earlier CVEs and monitor for continued exploitation attempts, as threat actors pivot rapidly between chained NetScaler flaws.