{"id":9872,"date":"2026-10-05T12:14:09","date_gmt":"2026-10-05T12:14:09","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9872"},"modified":"2026-10-05T12:14:09","modified_gmt":"2026-10-05T12:14:09","slug":"citrix-warns-of-actively-exploited-netscaler-flaw-days-after-zero-day-patch-rush","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9872","title":{"rendered":"Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively <a href=\"https:\/\/www.csoonline.com\/article\/4227488\/netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now-2.html\" target=\"_blank\" rel=\"noopener\">exploited zero-days<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The new vulnerability, tracked as <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697174\" target=\"_blank\" rel=\"noopener\">CVE-2026-88779<\/a>, is a memory-overflow <a href=\"https:\/\/www.csoonline.com\/article\/3823937\/cisa-fbi-call-software-with-buffer-overflow-issues-unforgivable.html\" target=\"_blank\" rel=\"noopener\">issue<\/a> that can cause a denial-of-service (DoS) condition on affected appliances. Citrix rated it 8.7 under CVSS 4.0 and said it has observed targeted attacks against unmitigated NetScaler deployments.<\/p>\n<p class=\"wp-block-paragraph\">The company said the attacks can repeatedly trigger the condition, potentially leaving the service unavailable.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met,\u201d the company said in a <a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway\/\" target=\"_blank\" rel=\"noopener\">blog post<\/a>. \u201cCustomers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Citrix has not attributed the activity to a particular threat actor or provided technical details on how the vulnerability is being exploited.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe reality is that the focus on edge appliances as an easy access mechanism to organizations is not changing,\u201d said watchTowr founder <a href=\"https:\/\/www.linkedin.com\/in\/benjamin-harris-sg\" target=\"_blank\" rel=\"noopener\">Benjamin Harris<\/a>, who was among the first to warn about the recent Citrix zero-days. \u201cAttackers are well aware that there is more to be found in these types of appliances in terms of vulnerabilities.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Exploitation needs a precondition<\/h2>\n<p class=\"wp-block-paragraph\">The flaw is not present in every NetScaler deployment. It requires the appliance to be configured for <a href=\"https:\/\/www.csoonline.com\/article\/4105030\/saml-authentication-broken-almost-beyond-repair.html\">SAML authentication<\/a>, either as a SAML service provider or identity provider, with the relevant SAML functionality used alongside Gateway or AAA virtual servers.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-88779 affects NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1-64.28, as well as 14.1 FIPS before 14.1-73.41 FIPS and 13.1 FIPS\/NDcPP before 13.1-37.282. Citrix said Secure Private Access Hybrid deployments using NetScaler instances are affected and must be upgraded.<\/p>\n<p class=\"wp-block-paragraph\">Administrators were advised to check for \u201cadd authentication samlAction\u201d and \u201cadd authentication samlIdPProfile\u201d entries in their configurations to determine whether the precondition applies.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOur analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data,\u201d Citrix said.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>NetScaler customers may have to patch twice in a week<\/h2>\n<p class=\"wp-block-paragraph\">The timing is concerning for enterprises that have just completed Citrix\u2019s previous emergency patch cycle. Last week, Citrix disclosed eight NetScaler vulnerabilities, including <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-88771\" target=\"_blank\" rel=\"noopener\">CVE-20206-88771 <\/a>and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-88772\" target=\"_blank\" rel=\"noopener\">CVE-2026-88772<\/a>, two critical flaws that the company said were already being exploited. The fixes affected 14.1 deployments to 14.1-73.37 and 13.1 deployments to 13.1-64.23.<\/p>\n<p class=\"wp-block-paragraph\">However, Citrix now says organizations that installed those releases must upgrade again if their appliances meet the SAML preconditions for CVE-2026-88779. The new fixed versions are 14.1-73.41, 13.1-64.28, 4.1-73.41 FIPS, and 13.1-37.282 for the applicable FIPS and NDcPP builds.<\/p>\n<p class=\"wp-block-paragraph\">There is a temporary mitigation for some already-patched deployments. Citrix says Global Deny List signatures can reduce exposure on NetScaler versions 14.1-73.37 through 73.40 and 13.1-64.23 through 64.27, provided the relevant virtual-patching functionality is enabled.<\/p>\n<p class=\"wp-block-paragraph\">Customers relying on this mitigation must verify if Global Deny List signatures are available on their NetScaler deployments by executing the \u201cshow appfw signatures\u201d command. Upgrading to the fixed builds, however, remains necessary wherever possible, the company noted. CISA has <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">added<\/a> the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, listing October 7 as the remediation deadline for US federal agencies.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days. The new vulnerability, tracked as CVE-2026-88779, is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9873,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9872"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9872"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9872\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9873"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}