> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

[SOURCE] CSO Online [DATE: 05/10/2026 12:14] [LANGUAGE: EN]
Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush
Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days. The new vulnerability, tracked as CVE-2026-88779, is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Citrix rated it 8.7 under CVSS 4.0 and said it has observed targeted attacks against unmitigated NetScaler deployments. The company said the attacks can repeatedly trigger the condition, potentially leaving the service unavailable. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met,” the company said in a blog post. “Customers should review their deployed versions and configurations, then install the relevant updated versions as soon as possible.” Citrix has not attributed the activity to a particular threat actor or provided technical details on how the vulnerability is being exploited. “The reality is that the focus on edge appliances as an easy access mechanism to organizations is not changing,” said watchTowr founder Benjamin Harris, who was among the first to warn about the recent Citrix zero-days. “Attackers are well aware that there is more to be found in these types of appliances in terms of vulnerabilities.” Exploitation needs a precondition The flaw is not present in every NetScaler deployment. It requires the appliance to be configured for SAML authentication, either as a SAML service provider or identity provider, with the relevant SAML functionality used alongside Gateway or AAA virtual servers. CVE-2026-88779 affects NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1-64.28, as well as 14.1 FIPS before 14.1-73.41 FIPS and 13.1 FIPS/NDcPP before 13.1-37.282. Citrix said Secure Private Access Hybrid deployments using NetScaler instances are affected and must be upgraded. Administrators were advised to check for “add authentication samlAction” and “add authentication samlIdPProfile” entries in their configurations to determine whether the precondition applies. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data,” Citrix said. NetScaler customers may have to patch twice in a week The timing is concerning for enterprises that have just completed Citrix’s previous emergency patch cycle. Last week, Citrix disclosed eight NetScaler vulnerabilities, including CVE-20206-88771 and CVE-2026-88772, two critical flaws that the company said were already being exploited. The fixes affected 14.1 deployments to 14.1-73.37 and 13.1 deployments to 13.1-64.23. However, Citrix now says organizations that installed those releases must upgrade again if their appliances meet the SAML preconditions for CVE-2026-88779. The new fixed versions are 14.1-73.41, 13.1-64.28, 4.1-73.41 FIPS, and 13.1-37.282 for the applicable FIPS and NDcPP builds. There is a temporary mitigation for some already-patched deployments. Citrix says Global Deny List signatures can reduce exposure on NetScaler versions 14.1-73.37 through 73.40 and 13.1-64.23 through 64.27, provided the relevant virtual-patching functionality is enabled. Customers relying on this mitigation must verify if Global Deny List signatures are available on their NetScaler deployments by executing the “show appfw signatures” command. Upgrading to the fixed builds, however, remains necessary wherever possible, the company noted. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, listing October 7 as the remediation deadline for US federal agencies.
[messages.read_original_source] →