Citrix disclosed CVE-2026-88779, the third actively exploited NetScaler zero-day in two weeks and a denial-of-service flaw triggered by a single crafted request against instances with SAML authentication enabled. CISA added it to the Known Exploited Vulnerabilities catalogue on 4 October. Researchers at watchTowr assessed exploitation likely began Friday, described it as "incredibly simple to trigger" — knocking an authentication gateway offline and denying legitimate users access behind it — and noted attempts carried shellcode implying an ambition to chain it toward remote code execution, while noting it can also accelerate the earlier CVE-2026-88771. Unlike the previous pair, Citrix responded faster with a mitigation and patch. The ACSC alert on critical NetScaler vulnerabilities noted reports from Australian organisations confirming exploitation, keeping the NetScaler estate high-priority for Australian government and critical-infrastructure operators.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-10-07 |
| Source | CyberScoop |
| Reliability | Tier 2 |
| CVEs | CVE-2026-88771, CVE-2026-88779 |