{
  "id": 12261865,
  "title": "Citrix NetScaler security snafus get even worse amid more 0-day reports",
  "url": "https://urgent.news/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-12261865",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T21:18:48.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232"
  },
  "original_language": "en",
  "account": "Citrix NetScaler appliances are facing a barrage of attacks, with new vulnerabilities being discovered and exploited by malicious actors. The latest issue, identified as CVE-2026-88779, is a memory overflow bug that can lead to denial of service attacks. This flaw only affects NetScaler ADC and Gateway appliances that are configured as SAML service providers or identity providers, which are commonly used for single sign-on authentication.\n\nCitrix confirmed on Friday that it is investigating a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. The vendor released a security advisory with patches on Saturday, urging vulnerable customers to install the updated versions as soon as possible. WatchTowr researchers suspect that the new vulnerability is being used to crash machines and potentially accelerate the exploitation of two earlier Citrix security holes (CVE-2026-88772 and CVE-2026-88771).\n\nCitrix has not provided specific details about the number of affected instances or the attackers' actions after exploiting the bug. However, they strongly encouraged customers to apply the fix to their NetScaler instances quickly. The US Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that CVE-2026-88779 is under active exploitation and advised federal agencies to patch the bug by Wednesday.\n\nSecurity experts emphasize the ease with which this vulnerability can be triggered, requiring only a single specially crafted request to render an appliance offline. WatchTowr's head of threat intelligence, Jake Knott, stressed that exploiting this authentication gateway can prevent legitimate users from accessing services. Citrix provided an indicator-of-compromise script for security teams to check exposed appliances for signs of compromise.",
  "summary": "The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Citrix NetScaler security snafus get even worse amid more 0-day reports",
        "url": "https://urgent.news/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day",
        "published": "2026-10-05T21:18:48.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}