Security News

New Citrix NetScaler Flaw Lets Attackers Crash Appliances, Even Patched Ones

The Record · 6 Oct 2026
Key Takeaway If your business runs NetScaler appliances, apply Citrix's mitigations and upgrades for all three vulnerabilities now, and check your devices for signs of compromise.

Citrix has confirmed a new vulnerability in its NetScaler appliances, tracked as CVE-2026-88779, that attackers are using to crash systems. Customers began reporting unusual incidents on Friday, including on appliances that were fully patched against last week's flaws. Citrix released an advisory and blog on Saturday, and the US Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch by Wednesday and carry out forensic triage.

The bug has a severity score of 8.7 out of 10. Citrix says it has seen targeted attacks on unmitigated NetScaler deployments that can lead to denial of service, and that repeated triggering may keep the service unavailable. It reports no identified impact on the integrity of customer data. NetScaler ADC and Gateway devices are used to manage traffic and authentication. Citrix has published mitigations that can be applied before an upgrade is installed, and credits Bishop Fox and watchTowr for helping identify the issue.

The new flaw has "no technical link" to two vulnerabilities announced last week, CVE-2026-88771 and CVE-2026-88772, according to watchTowr CEO Benjamin Harris. However, he suspects it has been used to deliberately crash machines, making exploitation of CVE-2026-88771 faster. Multiple security firms say those earlier bugs are still being widely exploited after patches were released, and CISA has warned that threat actors are actively exploiting them globally.

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.