By Dr. Christopher Kunz
Publication Date: 2026-10-03 08:35:00
Since the evening of October 2, 2026, an exploit for a new security vulnerability on Citrix NetScaler devices has apparently been circulating. The manufacturer warns in a blog post, security researchers claim to have observed malware on their test devices. Patches are not yet available at the moment.
According to British security expert Kevin Beaumont, it could be an evasion of the fix for the vulnerability disclosed last week, “Pitscaler” (CVE-2026-88771 / CVE-2026-88772). He writes: “So on one of the honeypots it’s running a downloaded (malware) binary. Both [honeypots, ed.] were patched, so new vuln.” It is apparently exploitable on the recently released latest version of the NetScaler operating system — a zero-day.
Other experts second this: “the watchTowr Labs team has now successfully reproduced this vulnerability.” This means that just one week after the last fatal vulnerability, an exploit for NetScaler systems capable of…



