Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, government, zero-day] · confidence: high · severity: critical · affected_sectors: [government] · au_impact: true

Citrix disclosed CVE-2026-88779, the third actively exploited NetScaler zero-day in two weeks and a denial-of-service flaw triggered by a single crafted request against instances with SAML authentication enabled. CISA added it to the Known Exploited Vulnerabilities catalogue on 4 October. Researchers at watchTowr assessed exploitation likely began Friday, described it as "incredibly simple to trigger" — knocking an authentication gateway offline and denying legitimate users access behind it — and noted attempts carried shellcode implying an ambition to chain it toward remote code execution, while noting it can also accelerate the earlier CVE-2026-88771. Unlike the previous pair, Citrix responded faster with a mitigation and patch. The ACSC alert on critical NetScaler vulnerabilities noted reports from Australian organisations confirming exploitation, keeping the NetScaler estate high-priority for Australian government and critical-infrastructure operators.

Attribute Detail
Sector Government
Date 2026-10-07
Source CyberScoop
Reliability Tier 2
CVEs CVE-2026-88771, CVE-2026-88779