Read as article
Citrix NetScaler Hit by Ninth Zero-Day, CISA Sets Patch Deadline
By @sharedot · · 8 pages
- Cybersecurity
- Citrix Netscaler
- Zero Day
- Cisa
Citrix issued emergency patches for its ninth exploited NetScaler zero-day, CVE-2026-88779, with CISA ordering federal agencies to patch by October 7.
A New Zero-Day Days After the Last One
Citrix has disclosed a fresh actively exploited vulnerability in its NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88779. The memory overflow flaw can crash authentication gateways with a single specially crafted request, producing a denial-of-service condition. Citrix confirmed the issue late Friday, released a security advisory with patches by Saturday night, and urged customers to install updates immediately. The company said it observed targeted attacks on unmitigated deployments, and that repeated exploitation can keep the affected service unavailable.
Only SAML Deployments Are Exposed
The flaw is not present in every NetScaler deployment. Exploitation requires the appliance to be configured as a SAML service provider or identity provider, with that functionality used alongside Gateway or AAA virtual servers. Administrators can check configurations for 'add authentication samlAction' or 'add authentication samlIdPProfile' entries to determine whether the precondition applies. Affected builds are 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, plus the corresponding FIPS and NDcPP branches, and Secure Private Access Hybrid deployments using affected NetScaler instances must also upgrade.
Why It Is Surprising
The disclosure lands just days after Citrix's previous emergency cycle, in which it patched eight vulnerabilities disclosed September 27 — including two critical zero-days, CVE-2026-88771 and CVE-2026-88772, exploited since late August. Organizations that installed those fixes must upgrade again if their appliances meet the new SAML preconditions. watchTowr researchers, who reproduced the bug on Friday, told The Register it is 'incredibly simple to trigger' and suspect attackers may be using the crash to accelerate exploitation of CVE-2026-88771, even though the new CVE is not technically related to the earlier eight.
The Evidence and Detection Effort
watchTowr's head of threat intelligence Jake Knott said exploitation is already occurring in the wild, and that disrupting an authentication gateway prevents legitimate users from reaching services behind it. According to CyberSecurityNews, researcher Kevin Beaumont separately reported a downloaded malware binary running on a patched honeypot, while administrators observed patched appliances rebooting after crafted SAML traffic crashed the nsaaad authentication service — though Citrix's confirmed vendor assessment is denial of service, with no identified impact on customer data integrity. Citrix has published an indicator-of-compromise script, though Knott cautioned a clean result is not definitive proof of safety.
Wider Campaign and the Stakes
The new flaw sits inside a broader wave of NetScaler attacks. Dozens of companies across multiple sectors, plus government agencies, were compromised in the earlier September zero-day attacks by suspected state-linked actors, and Cybersecurity Dive reports the Shadowserver Foundation identified more than 20,000 exposed, potentially vulnerable instances. Google Threat Intelligence Group and Mandiant identified custom web shells including Whipshot for command and control and Slapshot for persistence, and CISA released Sigma detection rules on Friday because patching alone may not remove infections where attackers wiped local logs.
Patch Now, Deadline Wednesday
CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to apply patches by Wednesday, October 7, under Binding Operational Directive 22-01. Fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 or later. Organizations unable to upgrade immediately can deploy Citrix's Global Deny List signatures to reduce exposure on versions 14.1-73.37 through 73.40 and 13.1-64.23 through 64.27, provided virtual patching is enabled — but Citrix says upgrading remains necessary wherever possible.
Sources
- news.lavx.hu › Citrix NetScaler hit by another zero-day as CISA orders federal agencies to patch by Wednesday
- theregister.com › Citrix NetScaler security snafus get even worse amid more 0-day reports
- csoonline.com › Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush
- cybersecuritynews.com › Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
- cybersecuritydive.com › Citrix issues patch for third exploited flaw in NetScaler
- securityaffairs.com › U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog
- technadu.com › CVE-2026-88779: Citrix NetScaler Zero-Day Exploited in Targeted Attacks