Citrix releases emergency updates for exploited NetScaler zero-day

 

Citrix releases emergency updates for exploited NetScaler zero-day

Citrix has released emergency security updates for a denial-of-service vulnerability in NetScaler ADC and NetScaler Gateway that is being exploited in targeted zero-day attacks.

Tracked as CVE-2026-88779, the vulnerability is a memory buffer flaw affecting NetScaler appliances configured with SAML authentication and Gateway or AAA functionality. Citrix says exploitation can lead to denial of service.

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service,” the company said, adding that repeatedly triggering the condition may leave the service unavailable, but its current analysis has found no impact to the integrity of customer data.

It’s not currently clear whether the underlying memory-handling issue could potentially be leveraged for remote code execution (RCE).

Citrix has released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to address CVE-2026-88779. Customers using FIPS deployments should upgrade to 14.1-73.41 FIPS, while NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282.

The company is also providing Global Deny Lists designed to block connections from known malicious IP addresses. However, Citrix recommends that customers treat the deny lists as an additional mitigation and install the security updates as soon as possible.

Security researchers have also observed a vulnerability impacting Rejetto HTTP File Server (HFS) being actively exploited in the wild. Tracked as CVE-2026-61500, the security issue allows attackers to forge session cookies and gain unauthorized access.

Separately, Fortra has released patches for multiple vulnerabilities in its Core Privileged Access Manager (BoKS), including three high-risk flaws: CVE-2026-79901 (an authentication bypass caused by predictable Active Directory service account passwords); CVE-2026-79898 (a command injection flaw in crlserver that could allow an authenticated attacker to execute shell commands as root on the BoKS Master); and CVE-2026-12627 (a stack buffer overflow in the autoregistration feature that could allow a remote attacker to cause memory corruption).

Back to the list