Government cybersecurity agencies in the US and Australia have issued urgent warnings about a fresh vulnerability affecting Citrix NetScaler appliances that enables attackers to render the systems unavailable. Exploitation attempts surfaced on Friday, with some incidents occurring on systems that had received all available security updates.

Citrix acknowledged late Friday that it was "tracking a newly observed issue" affecting certain customer-managed NetScaler installations, though the company stated this problem was distinct from vulnerabilities disclosed the previous week that had already triggered concern among security researchers.

The company released a security advisory and accompanying blog post on Saturday evening, designating the flaw as CVE-2026-88779. The following day, the Cybersecurity and Infrastructure Security Agency (CISA) instructed all US federal agencies to apply patches by Wednesday and perform forensic investigation.

Citrix NetScaler application delivery controllers (ADC) and Gateway products serve as critical infrastructure in large enterprises, handling network traffic routing and user authentication functions.

The flaw received a severity rating of 8.7 on a scale of 10. Citrix stated that it has documented "targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service." The company added, "If the condition is triggered repeatedly, the service may remain unavailable." Citrix further noted, "Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."

Citrix provided interim protective measures available before systems receive patched versions. The advisory acknowledges cybersecurity firms Bishop Fox and watchTowr for their role in discovering the vulnerability.

Benjamin Harris, founder and CEO of watchTowr, explained to Recorded Future News that a denial of service vulnerability permits attackers to incapacitate systems. While the current flaw has "no technical link" to last week's issues, Harris stated he "suspects it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster."

Citrix customers facing mounting pressure

Organizations relying on Citrix products continue managing the fallout from two earlier vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which became public the previous week. Despite the release of patches, security vendors have documented ongoing widespread exploitation of both flaws by malicious actors.

CISA released an additional advisory on Friday morning regarding the earlier bugs, stating it has received reports "confirming that threat actors are actively exploiting these vulnerabilities globally."

Mandiant, Google's cybersecurity division, reported having identified evidence of affected organizations across North America and Europe spanning the government, financial services, technology, education, and legal and professional services sectors through this exploitation operation.

"This campaign underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that [Google] has tracked across a range of threat actors," Mandiant stated. "These appliances — including Application Delivery Controllers, VPN gateways, and firewalls — remain attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network."