InfoSec News Nuggets – 10/05/2026
Brief
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix NetScaler administrators spent the weekend scrambling after attackers began exploiting a new zero-day, CVE-2026-88779, a high-severity memory overflow affecting NetScaler ADC and Gateway appliances configured as a SAML SP or IdP. The attacks surfaced when fully patched systems started rebooting on Friday, only days after admins were warned about two other exploited NetScaler zero-days dubbed PitScaler.
Citrix characterizes the flaw as a denial-of-service issue, but researcher Kevin Beaumont observed exploitation attempts against patched honeypots, including one that ran a downloaded malware binary, and admins found shell commands hidden in authentication requests meant to fetch a script that plants web shells. Citrix has released fixed builds 14. 1-73. 41 and 13. 1-64.
