Tag

Citrix Netscaler

All articles tagged with #citrix netscaler

New Citrix NetScaler SAML Flaw CVE-2026-88779 Exploited in Zero-Day Attacks
cybersecurity5 days ago

New Citrix NetScaler SAML Flaw CVE-2026-88779 Exploited in Zero-Day Attacks

Citrix released emergency patches for CVE-2026-88779, a high-severity memory buffer flaw in NetScaler ADC and Gateway appliances using SAML authentication. The vulnerability, which carries a CVSS score of 8.7, is being actively exploited in targeted attacks to cause denial-of-service conditions. While Citrix characterizes the issue as a service availability risk, researchers and administrators report evidence of remote code execution attempts, including malware payloads on patched systems. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7, 2026. This latest incident follows a wave of exploitation of earlier NetScaler vulnerabilities in September 2026, affecting dozens of organizations across government, healthcare, and finance sectors.

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching
cybersecurity11 days ago

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching

Citrix NetScaler appliances are facing active exploitation of critical zero-day vulnerabilities, specifically CVE-2026-88771, which allows unauthenticated remote code execution on default configurations. The flaw stems from improper input validation in a Perl script used for log analysis, enabling attackers to inject commands via crafted HTTP requests. While Citrix released patches for eight total vulnerabilities, the delay in official disclosure allowed threat actors to exploit the flaw in the wild before government agencies intervened. CISA has now mandated that U.S. federal agencies patch these systems by September 30, while Dutch hospitals have already restricted patient access to mitigate risks. The incident highlights a recurring pattern of Citrix NetScaler vulnerabilities being exploited before official advisories are published, prompting security firms to urge immediate isolation of affected devices.

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days
security12 days ago

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days

Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.

CitrixBleed Deepens: NetScaler Memory-Overread CVE-2026-8451 Exposed
security3 months ago

CitrixBleed Deepens: NetScaler Memory-Overread CVE-2026-8451 Exposed

Security researchers reveal CVE-2026-8451, a memory overread in Citrix NetScaler appliances (ADC/Gateway) triggered when configured as a SAML IdP. A lax XML attribute parser can overread input, leaking data such as IDs and assertion URLs via the NSC_TASS cookie and potentially exposing memory contents. Citrix has issued patches after extensive analysis and demonstrations by watchTowr, highlighting ongoing memory-management weaknesses in NetScaler devices.

Dual memory-overread flaws unlock Citrix NetScaler doors (CVE-2026-3055) Part 2
security6 months ago

Dual memory-overread flaws unlock Citrix NetScaler doors (CVE-2026-3055) Part 2

Security researchers from watchTowr Labs report that CVE-2026-3055 encompasses at least two memory-overread flaws in Citrix NetScaler. Exploitation hinges on an empty wctx parameter in /wsfed/passive?wctx, leaking memory (via the NSC_TASS cookie) and potentially exposing authenticated admin session IDs. In-the-wild activity has begun, suggesting that patches may not cover all variants. The post includes a Detection Artifact Generator for defenders and notes that a further instance was reported to Citrix, highlighting ongoing risk for misconfigured NetScaler deployments (e.g., when used as a SAML IDP).