The Maivia Gazette

Verified AI news, every morning

Security

Citrix rushes out fixes for a third NetScaler zero-day in a week, this one aimed at SAML deployments

CVE-2026-88779 caused denial-of-service conditions on appliances that had already been patched against two other exploited flaws. Researchers are checking whether it can also be used for code execution.

A stone gatehouse at night with a patched iron portcullis stuck halfway down as waves of sand pile against it.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

Citrix has confirmed that a new NetScaler zero-day, CVE-2026-88779, is being exploited in targeted attacks. It comes days after administrators patched two other actively exploited flaws, CVE-2026-88771 and CVE-2026-88772. According to SecurityWeek, administrators first reported on Friday that fully patched NetScaler systems were rebooting. The new flaw is a memory buffer issue with a CVSS score of 8.7. It affects NetScaler ADC and NetScaler Gateway instances configured as a SAML service provider or identity provider. "Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company said. It added that repeated triggering can keep the service unavailable and that it has found no impact on the integrity of customer data. BleepingComputer reports that researchers are investigating whether the flaw could also allow remote code execution. Early Sunday, Citrix released fixed versions 14.1-73.41 and 13.1-64.28. FIPS deployments should move to 14.1-73.41 FIPS, and FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282. Citrix is also providing Global Deny Lists that block known malicious IP addresses. Because many organizations rely on NetScaler appliances for remote access and authentication, the third exploited zero-day in a week puts more pressure on teams that have only just finished the previous emergency patching.

Sources

  1. SecurityWeekExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierPublished · fetched
  2. BleepingComputerCitrix patches NetScaler SAML zero-day exploited in attacksPublished · fetched
  3. The Hacker NewsNew NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments OfflinePublished · fetched

Also in this edition