Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix security patch release for CVE-2026-88779

Security Patch Release
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS deployments. The vendor shipped 14.1-73.41 and 13.1-64.28, and told customers to install the updates immediately. Global Deny Lists were also provided as a supplementary block list for known malicious IPs.

Related Happenings

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score54 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...

Citrix security patch release for CVE-2026-13474

Security Patch Release
H score35 First: 01.07.2026 06:54 Last: 01.07.2026 06:54 Sources 1

About this happening: Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could enable arbitrary file reads or denial of servi...

Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498

Security Patch Release
H score44 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...

Latest development: 21.05.2026 12:52

Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.

CISA KEV order for CVE-2026-3055 on Citrix appliances

Public Sector Action
H score34 First: 31.03.2026 10:05 Last: 31.03.2026 10:05 Sources 1

About this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...

Cloud Software Group NetScaler urgent remediation advisory

Advisory/Mitigation
H score44 First: 25.03.2026 17:52 Last: 25.03.2026 17:52 Sources 1

About this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...

Latest development: 31.07.2026 20:35

Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.

Timeline

  1. 05.10.2026 00:58 1 articles · 2h ago

    Patched NetScaler appliances begin rebooting during suspected exploitation

    Initial Disclosure

    NetScaler administrators reported that recently patched NetScaler ADC and NetScaler Gateway appliances were unexpectedly rebooting, including multiple customers running NetScaler 14.1-73.37 and appliances rebuilt from fresh images. The reboot pattern suggested either a new flaw or active exploitation, while the root cause was still unclear.

    Show sources
  2. 05.10.2026 00:58 1 articles · 2h ago

    Crafted SAML usernames trigger nsaaad crashes on patched NetScaler appliances

    Exploitation Observed

    As administrators continued investigating the crashes, Citrix published a security notice on Friday saying its engineering and support teams were tracking a newly observed issue in customer-managed NetScaler deployments configured with authentication samlAction or authentication samlIdPProfile. One administrator saw crafted authentication usernames containing shell commands that downloaded a payload from 213.209.159[.]55, saved it as /v, and executed the file immediately before three confirmed nsaaad crash sequences on one appliance, and other researchers reported patched NetScaler honeypots crashing after requests from multiple source IP addresses. Kevin Beaumont later said one patched honeypot was running a downloaded malware payload, suggesting the flaw could go beyond denial of service.

    Show sources
  3. 05.10.2026 00:58 2 articles · 2h ago

    Citrix ships emergency NetScaler fixes for CVE-2026-88779

    Mitigation Patch Update

    Early Sunday morning, Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix CVE-2026-88779. For FIPS deployments, customers were told to upgrade to 14.1-73.41 FIPS or 13.1-37.282 on the 13.1 branch, and Citrix also provided Global Deny Lists that block access from known malicious IP addresses while urging customers to install the security updates immediately.

    Show sources
  4. 05.10.2026 00:58 1 articles · 2h ago

    CISA adds CVE-2026-88779 to the Known Exploited Vulnerabilities catalog

    Legal Policy Action Update

    On Sunday, CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, confirming the flaw was being actively exploited and giving FCEB agencies until October 7 to mitigate it.

    Show sources