Citrix on Saturday urged customers to immediately patch a memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway, which was being exploited as a zero-day.
The vulnerability, tracked as CVE-2026-88779, could lead to a denial-of-service condition on customer-managed NetScaler deployments when certain preconditions were met, the company said.
Citrix said it observed targeted attacks on unmitigated NetScaler systems and noted the system could be rendered unavailable in cases where repeated attacks had taken place. Citrix added it has not fully identified how these attacks could impact the integrity of customer data.
The preconditions are based on whether NetScaler deployments are authenticated using security assertion markup language in conjunction with Gateway or AAA functionality.
The Cybersecurity and Infrastructure Security Agency on Sunday added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have until Wednesday to mitigate the flaw in their respective environments. There is no known link to ransomware.
Response disruptions
The denial-of-service condition was discovered at a time when thousands of Citrix customers are scrambling to address two zero-day flaws in the same products. Citrix previously warned about a remote code execution flaw, tracked as CVE-2026-88771, and a memory overflow vulnerability, tracked as CVE-2026-88772, that security researchers said have been exploited since late August.
Shadowserver Foundation has identified more than 20,000 instances that are exposed and potentially vulnerable to exploitation.
Dozens of companies across multiple sectors, as well as government agencies, have been compromised in the attacks by suspected state-linked actors.
Citrix warned that successful exploitation of the vulnerabilities could lead to a variety of impacts, including remote code execution, denial of service, HTTP request smudging, policy bypass and other conditions. Researchers from Google Threat Intelligence Group and Mandiant Consulting identified custom web shells that had been deployed, including Whipshot for command and control and Slapshot for persistence.
Researchers last week warned that patching alone would not necessarily resolve systems with suspected infections. CISA on Friday released Sigma detection rules to help security teams identify a potential compromise situation.
“Prior to these rules being shared, organizations relied on Citrix’s built-in triage tools or ran manual checks directly on the appliance,” Tyler McLellan, principal threat research analyst at GTIG, told Cybersecurity Dive. While Citrix’s scanners are a valuable first step for on-device triage, any local assessment would be inherently limited if the attacker has already wiped the local logs, which they did in some cases.”
Citrix said that customers should check their NetScaler deployments to make sure they meet the precondition. The company released mitigations that can be used via the Global Deny List feature.