Urgent.News

What's breaking now, across thousands of outlets.

Tech

Citrix NetScaler security snafus get even worse amid more 0-day reports

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service

Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix NetScaler appliances are facing a barrage of attacks, with new vulnerabilities being discovered and exploited by malicious actors. The latest issue, identified as CVE-2026-88779, is a memory overflow bug that can lead to denial of service attacks. This flaw only affects NetScaler ADC and Gateway appliances that are configured as SAML service providers or identity providers, which are commonly used for single sign-on authentication.

Citrix confirmed on Friday that it is investigating a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. The vendor released a security advisory with patches on Saturday, urging vulnerable customers to install the updated versions as soon as possible. WatchTowr researchers suspect that the new vulnerability is being used to crash machines and potentially accelerate the exploitation of two earlier Citrix security holes (CVE-2026-88772 and CVE-2026-88771).

Citrix has not provided specific details about the number of affected instances or the attackers' actions after exploiting the bug. However, they strongly encouraged customers to apply the fix to their NetScaler instances quickly. The US Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that CVE-2026-88779 is under active exploitation and advised federal agencies to patch the bug by Wednesday.

Security experts emphasize the ease with which this vulnerability can be triggered, requiring only a single specially crafted request to render an appliance offline. WatchTowr's head of threat intelligence, Jake Knott, stressed that exploiting this authentication gateway can prevent legitimate users from accessing services. Citrix provided an indicator-of-compromise script for security teams to check exposed appliances for signs of compromise.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Moldova Rises Eight Places in Global Startup Ranking as Funding Expands

Moldova rose eight places to 82nd in StartupBlink’s 2026 Global Startup Ecosystem Index, according to an announcement issued by Startup Moldova Foundation in Chișinău on October 5.

  • Moldova climbs to 82nd place in global startup ranking.
  • Ecosystem score increases by 91.9% from 2025 to 2026.
  • Over $17 million in funding secured by local startups in 2025.

CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt

CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt Microsoft Authenticator was the control most organisations reached for once they moved past SMS codes.

  • Microsoft Authenticator App functions as a comprehensive credential store, not just a second factor.
  • CVE-2026-80097 vulnerability exposes improper authentication, allowing privilege elevation.
  • Microsoft recommends strong device passcodes and limiting app accounts to mitigate risk.

More from Monday 5 October →