Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Citrix discloses third actively exploited NetScaler zero-day in less than a week

Дата публикации: 05-10-2026 23:07:17

The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days.
The post Citrix discloses third actively exploited NetScaler zero-day in less than a week appeared first on CyberScoop.


Основное содержимое страницы с новостью.

Citrix customers just got through back-to-back weekends filled with varying levels of uncertainty and worry, as yet another actively exploited zero-day vulnerability was discovered in Citrix NetScaler products.

Researchers and security experts said the vulnerability — CVE-2026-88779 — is less concerning because exploitation triggers denial of service and only impacts instances that have SAML (security assertion markup language) enabled. 

“This means it doesn’t work out of the box against every NetScaler deployment,” Jake Knott, head of threat intelligence at watchTowr, told CyberScoop. “While this is very inconvenient, it doesn’t have organizations scrambling to trigger incident response.”

Citrix was much quicker and consistent in alerting customers to the emerging threat Friday, and followed up the next day with a more detailed blog post and security advisory that contained a patch for the high-severity defect. 

“After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix,” a company spokesperson said in a statement. “The fix for this issue is available, and we urge all customers to quickly apply it to their NetScaler instance.”

The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Sunday.

The vendor’s response also provided some relief for customers and researchers who spent much of the previous weekend rushing to assess widespread rumors of other defects in the assailed network edge gateways. In that case, Citrix took most of the weekend to confirm attackers were actively exploiting a pair of NetScaler zero-days, some of which researchers said remained undetected for at least three weeks.

“Citrix did a better job with their response to this vulnerability,” and took steps that enabled customers to make their own risk-based decisions with more currently available information, said Joe Toomey, vice president of underwriting security at insurance provider Coalition. 

“Although it’s difficult to celebrate given this is the third publicly-exploited NetScaler zero-day vulnerability in a two-week window, it is a step in the right direction,” he added. 

Citrix declined to say how many customers are impacted by the latest zero-day or when the first instance of exploitation occurred. Yet, Knott at watchTowr said exploitation likely began Friday. 

The newer defect doesn’t share any technical links with the pair of zero-days Citrix disclosed less than a week prior, but it can accelerate one of those vulnerabilities — CVE-2026-88771 — by intentionally crashing machines to speed up exploitation, Knott said.

While risk is currently perceived low for CVE-2026-88779, it is “incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” Knott added. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.”

Toomey also described the denial-of-service vulnerability as less serious than the previous week’s actively exploited zero-days. Yet, he noted, exploitation attempts of CVE-2026-88779 “clearly contain shellcode that implies that the threat actor believes they can use this vulnerability, or chain it with another vulnerability, in order to achieve remote-code execution.”

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings08.529-09-2026
2Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected011.829-09-2026
3Cisco warns customers of actively exploited zero-day in email gateways08.4415-09-2026
4Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation09.2627-09-2026
5CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
6Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung09.0327-09-2026
7Две zero-day без пароля открыли хакерам корпоративные VPN015.5628-09-2026
8WaterISAC reckons with range of threats after summer of cyberattacks09.1830-09-2026
9Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members014.2801-10-2026
10Server am Samstagmorgen herunterfahren: Kiteworks warnt Admins vor Zero-Day013.4525-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.57. Источник: www.cyberscoop.com.