US, Australia warn of latest Citrix vulnerability after NetScaler advisory
A new vulnerability is giving cybercriminals the ability to crash Citrix NetScaler appliances, prom 2026-10-5 17:33:14 Author: therecord.media(查看原文) 阅读量:4 收藏

A new vulnerability is giving cybercriminals the ability to crash Citrix NetScaler appliances, prompting urgent warnings from multiple government agencies.

Customers began reporting strange exploitation incidents on Friday, even on appliances that were up to date on all patches. 

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.

By Saturday evening, Citrix released a security advisory and a blog addressing the vulnerability, tagging it as CVE-2026-88779. On Sunday, the Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal agencies to patch the bug by Wednesday and conduct forensic triage. 

Citrix NetScaler application delivery controllers (ADC) and Gateway devices are used by large organizations to manage traffic and authentication.

The vulnerability carries a severity score of 8.7 out of 10 and Citrix confirmed that it saw “targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.”  

“If the condition is triggered repeatedly, the service may remain unavailable,” Citrix said. “Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

Citrix also released some mitigations that can be used before an upgrade is installed. In the advisory, Citrix credits cybersecurity firms Bishop Fox and watchTowr for helping identify the issue. 

Benjamin Harris, founder and CEO of watchTowr, told Recorded Future News that a denial of service bug allows cybercriminals to crash systems. 

While the latest bug has “no technical link” to the issues identified last week, Harris said he “suspects it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster.” 

Battered Citrix customers

Customers of Citrix are still addressing the exploitation of two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, announced last week. After patches were released for the two bugs, multiple cybersecurity firms said the issues were still being exploited widely by cybercriminals. 

CISA released its own follow-up advisory on Friday morning about the bugs, warning that it has received reports “confirming that threat actors are actively exploiting these vulnerabilities globally.”

Google cybersecurity firm Mandiant added that it has evidence of organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors that were likely impacted by this exploitation campaign.

“This campaign underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that [Google] has tracked across a range of threat actors,” they said. 

“These appliances — including Application Delivery Controllers, VPN gateways, and firewalls — remain attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network.”

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/us-australia-warn-of-latest-citrix-vulnerability
如有侵权请联系:admin#unsafe.sh