Citrix NetScaler zero-day reportedly hits appliances patched for earlier flaws
SecurityWeek reports Citrix identified CVE-2026-88779 as a memory overflow affecting SAML-configured NetScaler systems.
TLDR
SecurityWeek reports that NetScaler appliances updated for two earlier flaws began rebooting as Citrix confirmed exploitation of a new zero-day, CVE-2026-88779. Citrix says attacks on unmitigated SAML-configured systems can disrupt service and that it has not identified an impact on customer data integrity. Researcher Kevin Beaumont reported exploitation attempts against patched honeypots. CISA added the flaw to its known-exploited list on October 4 and told federal agencies to address it by October 7.
Combined views
561
1 Source, first seen ago