
Citrix rushes out patch as attackers target third NetScaler flaw within days
A fresh software defect allows attackers to take essential network gateways offline by triggering simple system crashes.
6 Oct 2026
Citrix has published an emergency software repair after attackers began striking network devices that handle login traffic and application routing for large institutions. The company identified the flaw as CVE-2026-88779 and assigned it a severity rating of 8.7 out of 10.
The flaw allows unauthorized users to knock NetScaler Application Delivery Controllers and Gateway systems offline. To take a machine down, an intruder only needs to transmit a single tailored digital inquiry across the internet.
The software error results in a denial of service, a condition where legitimate staff members cannot reach the workplace tools located behind the network gateway. Repeated strikes can leave machines down indefinitely, though Citrix stated it has found no evidence that customer data has been altered or stolen.
Only specific systems face this danger. Machines remain safe unless administrators have switched on security assertion markup language, a common identity method known as SAML. Security researchers noted that because of this requirement, default setups are not open to immediate attack.
The breach came to light late on Friday when network administrators observed unusual incidents on gateways that were fully updated with all existing patches. Citrix acknowledged it was following a new issue that same evening, then issued safety instructions alongside a permanent repair on Saturday.
Citrix commended security companies Bishop Fox and watchTowr for assisting with the discovery of the flaw. Jake Knott, threat intelligence head at watchTowr, suggested active exploitation probably began on Friday.

United States authorities acted quickly following the advisory. On Sunday, the Cybersecurity and Infrastructure Security Agency placed the software flaw on its list of actively abused weaknesses and instructed all civilian federal agencies to install the update by Wednesday.
This emergency marks the third time in two weeks that attackers have struck zero-day weaknesses in NetScaler hardware. A zero-day defect is a software bug discovered and used by hackers before the software builder has created a fix.
The newest flaw has no direct technical connection to the two flaws Citrix revealed during the prior week, designated CVE-2026-88771 and CVE-2026-88772. However, experts from watchTowr warned that intruders appear to use the new crashing technique to accelerate their attacks against the earlier CVE-2026-88771 weakness.
Joe Toomey, a security executive at insurance firm Coalition, observed that attack traffic tied to the new bug contains raw execution code. He stated this code indicates intruders are attempting to combine the crash with other flaws to gain deeper command over the target hardware.
The earlier pair of zero-days caused widespread harm across global networks. Mandiant reported finding evidence of compromised organizations throughout North America and Europe, spanning government offices, colleges, banks, technology providers, and legal practices.
Mandiant explained that edge equipment like firewalls and gateways remains a prime target for online criminals. These devices face the open web directly, operate beyond ordinary desktop surveillance software, and routinely handle user passwords that help attackers infiltrate deeper into internal systems.
Security specialists commended Citrix for moving faster than it did the previous weekend, when the vendor needed days to confirm ongoing attacks that had operated in secret for several weeks. Citrix has declined to reveal how many clients suffered attacks or state when the first breach occurred.