thehackernews.com 5 Oct 2026, 14:20 UTC

Hackers Exploit Citrix NetScaler and FortiMail Zero Days in Attacks

ON 05 October 2026, The Hacker News reports ongoing exploitation of two high‑severity zero‑day flaws in enterprise products, highlighted as Threat of the Week. Citrix has disclosed that CVE‑2026‑88779, a memory overflow affecting NetScaler ADC and NetScaler Gateway, has been actively exploited in targeted attacks. Citrix states that successful exploitation can lead to a denial‑of‑service under certain deployment conditions and requires NetScaler to be configured as a SAML service provider or identity provider.

The article notes Fortinet’s FortiMail is also under active exploitation of a critical vulnerability, CVE‑2026‑104286, which allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests, with CISA warnings accompanying FortiMail advisories. Fortinet’s assessment and CISA guidance are cited as the primary evidence of exploitation in the wild.

The piece frames the incidents as part of a broader pattern where simple misconfigurations or overlooked details enable intruders, and it underscores the immediate need for patching and verification of exposure. It also summarises that Citrix has issued security updates and that FortiMail is under active exploitation, urging organisations to apply fixes for affected versions and to review access controls around SAML deployments and FortiMail deployments.

While the article aggregates multiple security stories, the NetScaler CVE‑2006‑88779 and FortiMail CVE‑2026‑104286 specifics are presented as confirmed high‑risk exploitation with public evidence from vendor advisories and CISA.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline