Citrix has disclosed a third actively exploited NetScaler zero-day, CVE-2026-88779, less than a week after two prior disclosures. The vulnerability triggers a denial-of-service and only affects NetScaler instances with SAML enabled; Citrix published a mitigation and a fix and urged customers to apply the update quickly.
NetScaler zero-day details and impact
“This means it doesn’t work out of the box against every NetScaler deployment,” said Jake Knott, head of threat intelligence at watchTowr. “While this is very inconvenient, it doesn’t have organizations scrambling to trigger incident response.”
A Citrix spokesperson said: “After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix. The fix for this issue is available, and we urge all customers to quickly apply it to their NetScaler instance.”
The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Sunday.
Citrix declined to say how many customers are impacted by the latest zero-day or when the first instance of exploitation occurred. Knott said exploitation likely began Friday. The new defect does not share technical links with the pair of zero-days Citrix disclosed less than a week prior, but it can accelerate one of those vulnerabilities — CVE-2026-88771 — by intentionally crashing machines to speed up exploitation, Knott said.
“While risk is currently perceived low for CVE-2026-88779, it is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” Knott added. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.”
Joe Toomey, vice president of underwriting security at insurance provider Coalition, said Citrix “did a better job with their response to this vulnerability,” and took steps that enabled customers to make their own risk-based decisions with more currently available information. “Although it’s difficult to celebrate given this is the third publicly-exploited NetScaler zero-day vulnerability in a two-week window, it is a step in the right direction,” he added. Toomey also noted that exploitation attempts of CVE-2026-88779 “clearly contain shellcode that implies that the threat actor believes they can use this vulnerability, or chain it with another vulnerability, in order to achieve remote-code execution.”

