Opens in a new tab

Security Roundup, October 5: NetScaler SAML Zero-Day and Rejetto HFS Flaw Under Active Attack

  • Home
  • Blog
  • Security Roundup, October 5: NetScaler SAML Zero-Day and Rejetto HFS Flaw Under Active Attack
Server rack breach illustrating a NetScaler SAML Zero-Day exploit in progress

Citrix NetScaler administrators gained a clear, immediate action this week: install the emergency releases 14.1-73.41 and 13.1-64.28 to close a memory-overflow flaw that is rebooting appliances that were already patched against the two prior zero-days. A second, separate defect in the Rejetto HTTP File Server is now being weaponized to forge administrator sessions and run code on the host, and CISA has added a new entry to the Known Exploited Vulnerabilities catalog. Together these three items cover most exposed internet-facing services a mid-size business runs today.

Citrix NetScaler SAML Zero-Day Forces a Second Patch Cycle

Citrix confirmed CVE-2026-88779, a memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway instances configured as a SAML SP or SAML IdP. The flaw carries a CVSS score of 8.7 and has been used in targeted attacks against unmitigated deployments. Citrix describes the observed impact as denial-of-service: if the condition is triggered repeatedly, the service can stay down. Citrix has also stated that its analysis has not identified an impact on the integrity of customer data, though separate reporting indicates researchers are still investigating whether the same bug can be used for remote code execution.

The issue surfaced on Friday when administrators reported reboots on NetScaler appliances that had already been updated to fix the two earlier actively exploited zero-days, CVE-2026-88771 and CVE-2026-88772. Logs reviewed by affected admins showed authentication requests carrying shell commands hidden in the username field, and a researcher running honeypot instances confirmed exploitation attempts against appliances that were already patched.

The fix shipped early Sunday morning as NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28. For FIPS deployments the target release is 14.1-73.41 FIPS; NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282. Citrix is also distributing Global Deny Lists that block known malicious IP addresses, and the company recommends installing the new updates as soon as possible rather than relying on deny lists alone.

To check whether a given appliance is exposed, run one of these commands on the device:

  • For SAML SP configurations: add authentication samlAction
  • For SAML IdP configurations: add authentication samlIdPProfile

Any organization that patched NetScaler last week to remediate CVE-2026-88771 or CVE-2026-88772 must patch again to address CVE-2026-88779. The same appliances that were safe on Monday are the ones rebooting today.

Rejetto HFS Flaw Lets Attackers Forge Admin Sessions and Run Code

A vulnerability in Rejetto HTTP File Server is being actively exploited. The flaw lets an attacker forge an administrator session and then achieve remote code execution on the host running HFS. Because HFS is a small, often overlooked file-sharing utility that is commonly left running on older Windows systems for ad-hoc transfers, the practical risk is that an attacker who reaches the HFS interface can quietly take administrative control of the box it runs on.

HFS installations have been a persistent target for years because the tool is widely deployed, frequently unpatched, and reachable from the internet in many environments. The combination of session forgery and remote code execution puts any exposed instance at the top of an attacker’s triage list.

What to do now: identify any host on the network running HFS, take it offline if it is reachable from the internet, and update to the latest Rejetto HFS build. Restrict HFS to trusted internal subnets, place it behind a reverse proxy with authentication, and remove it entirely from systems that no longer need a quick-share file server. Treat any host that has run an exposed HFS instance as compromised until logs can be reviewed for unauthorized administrative sessions.

CISA Adds a New Vulnerability to the Known Exploited Vulnerabilities Catalog

CISA added one new entry to its Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026. Inclusion on the KEV list means there is reliable evidence of active exploitation in the wild, and U.S. federal civilian agencies are required to remediate catalog entries on the published due date. Many private-sector patch-management programs treat KEV additions as a hard deadline as well, because KEV entries are a strong signal that proof-of-concept exploit code is circulating.

What to do now: pull today’s KEV addition into your vulnerability management queue today, prioritize remediation of the listed product over lower-severity backlogs, and confirm that your scanning tools are flagging the affected product and version. If your environment does not run the affected software, document that fact so the finding closes cleanly and does not reopen on the next scan cycle.

What to Do This Week

  • Patch every Citrix NetScaler ADC and NetScaler Gateway instance to 14.1-73.41 or 13.1-64.28, and use 14.1-73.41 FIPS or 13.1-37.282 for FIPS and NDcPP deployments.
  • Confirm whether any appliance is configured as a SAML SP or SAML IdP, since those configurations are the ones in scope for CVE-2026-88779.
  • Apply Citrix’s Global Deny Lists as a temporary mitigation while you complete the patch rollout.
  • Inventory every host running Rejetto HTTP File Server, take exposed instances offline, patch, and restrict future access to trusted networks.
  • Pull today’s CISA KEV addition into the patch queue and schedule remediation on the KEV due date.
  • Review authentication and admin-session logs on any internet-facing appliance or file server that was unpatched during the past 72 hours.

FAQ

What is CVE-2026-88779?

CVE-2026-88779 is a memory-overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that is being exploited as a denial-of-service attack against appliances configured as a SAML SP or SAML IdP. Citrix rates the flaw as high severity with a CVSS score of 8.7.

Which NetScaler versions fix CVE-2026-88779?

Citrix released NetScaler ADC and NetScaler Gateway 14.1-73.41 and 13.1-64.28 to fix the flaw. FIPS deployments should move to 14.1-73.41 FIPS, and NetScaler ADC FIPS and NDcPP customers on the 13.1 branch should install 13.1-37.282.

Do appliances already patched against CVE-2026-88771 and CVE-2026-88772 still need an update?

Yes. CVE-2026-88779 is a separate flaw that emerged days after the earlier two were patched, and appliances that were current against the older CVEs are the ones now rebooting. A second patch cycle is required.


This article summarizes reporting from thehackernews.com, thehackernews.com, twitter.com, localhost, thehackernews.com.

← All Articles