← Back to feed
DFIREmerging1 sourceOct 5, 2026 · 10:53via AboutDFIR

InfoSec News Nuggets – 10/05/2026

Brief

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix NetScaler administrators spent the weekend scrambling after attackers began exploiting a new zero-day, CVE-2026-88779, a high-severity memory overflow affecting NetScaler ADC and Gateway appliances configured as a SAML SP or IdP. The attacks surfaced when fully patched systems started rebooting on Friday, only days after admins were warned about two other exploited NetScaler zero-days dubbed PitScaler.

Citrix characterizes the flaw as a denial-of-service issue, but researcher Kevin Beaumont observed exploitation attempts against patched honeypots, including one that ran a downloaded malware binary, and admins found shell commands hidden in authentication requests meant to fetch a script that plants web shells. Citrix has released fixed builds 14. 1-73. 41 and 13. 1-64.

Read more on AboutDFIR→