HelpnetSecurity

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)


CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable,” the vendor stated.

“Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

Attacks observed after patching spree

Bishop Fox and watchTowr researchers have been credited with flagging CVE-2026-88779, and the latter have reproduced it, but have yet to share technical details.

Reddit users have been reporting that their organizations’ NetScaler appliances have been hit by crashes and reboots after they’ve upgraded to patch eight vulnerabilities, including two actively exploited zero-days: CVE-2026-88771 and CVE-2026-88772.

Apparently, the attackers are trying to exploit the flaw to download and run a script to install webshells.

Security researcher Kevin Beaumont reported attacks on his honeypots, from multiple IP addresses, and said he found a downloaded malware binary on one of them.

A threat hunter working at insurance company Geico has shared a SIGMA rule for identifying probing/scanning and exploitation attempts, but it’s still unclear if exploitation of this vulnerability can lead to successful remote code execution.

Affected versions and mitigation

The following supported NetScaler versions are affected by CVE-2026-88779:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.28
  • Citrix NetScaler ADC FIPS before 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.282

CVE-2026-88779 can be exploited on vulnerable on-prem NetScaler deployments only if the appliance has been configured to use SAML authentication (either as a service provider or an identity provider) in conjunction with Gateway or AAA functionality.

Citrix advised customers to upgrade to a fixed version and has pushed out signatures, usable via the Global Deny List feature, to reduce exposure while they plan the upgrade. The signatures should block access from known malicious IP addresses.

“Citrix provides an indicator of compromise script through NetScaler Console to check affected appliances for signs of compromise. Citrix notes that the latest script version can report a false positive about suspicious nobody processes even when it finds no compromise, so administrators should review results carefully and preserve evidence before applying the update,” watchTowr advised.

CISA has ordered US federal civilian agencies to address the vulnerability by October 7 and to check for compromise.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!



Source link