All Articles

Zero-Days in Action: NetScaler and HFS Exploits Demand Immediate Response

October 5, 2026 5 min read By The Vici Tech Solutions Team
VulnerabilitiesZero-DayThreat IntelligenceCyber Security

Two Critical Vulnerabilities Under Active Exploitation

This week brings a stark reminder that the window between vulnerability disclosure and active exploitation continues to shrink. Two critical flaws are seeing active exploitation right now: CVE-2026-88779 affecting Citrix NetScaler and CVE-2026-61500 in Rejetto HTTP File Server. Both vulnerabilities arrived on CISA's Known Exploited Vulnerabilities catalog within days of disclosure, signaling widespread targeting.

For IT managers and security teams, this isn't just another patch cycle. These are real-world attacks happening now against production systems.

CVE-2026-88779: NetScaler Zero-Day Targets SAML Deployments

Citrix released emergency patches on Friday for a high-severity denial-of-service vulnerability in NetScaler ADC and NetScaler Gateway. The flaw, tracked as CVE-2026-88779, has been exploited as a zero-day in targeted attacks. According to SecurityWeek, exploitation hit appliances that had been patched just days earlier for two other vulnerabilities, suggesting attackers pivoted quickly to this new vector.

The vulnerability impacts SAML authentication implementations specifically. While Citrix has classified this as a denial-of-service issue due to improper restriction of operations within memory bounds, the targeting of SAML deployments is significant. SAML serves as the authentication backbone for many enterprise applications, and disrupting it can lock users out of critical business systems.

Why This Matters

NetScaler appliances sit at the perimeter of many enterprise networks, handling authentication and application delivery. A successful exploit can:

  • Disrupt authentication services across the organization
  • Impact access to multiple downstream applications
  • Create cascading availability problems
  • Potentially serve as reconnaissance for follow-on attacks

The fact that CISA added CVE-2026-88779 to the KEV catalog on October 4 means federal agencies must patch within their assigned deadlines, and private sector organizations should treat this with equivalent urgency.

Immediate Actions for NetScaler Users

  • Patch immediately: Apply Citrix's emergency updates without delay
  • Review logs: Check for unusual SAML authentication failures or memory-related errors
  • Monitor authentication services: Implement enhanced monitoring for NetScaler appliances
  • Verify configurations: Ensure SAML implementations follow vendor hardening guidelines
  • Test failover: Verify backup authentication methods are functional

CVE-2026-61500: Rejetto HFS Admin Session Forgery and RCE

Rejetto HTTP File Server, a popular file-sharing application, contains a critical vulnerability with a CVSS score of 9.3. VulnCheck reports active exploitation attempts targeting CVE-2026-61500, which allows attackers to recover the session-cookie signing key.

Once attackers obtain this key, they can forge administrative sessions and achieve remote code execution. This is a complete compromise scenario: from unauthenticated attacker to full administrative control of the server.

What makes this vulnerability particularly noteworthy is that it was discovered by AI, according to SecurityWeek. This represents an interesting inflection point where AI-assisted vulnerability research is finding flaws that are immediately weaponized.

Attack Chain and Risk Profile

The vulnerability enables a straightforward attack path:

  1. Attacker recovers session-cookie signing key through the vulnerability
  2. Attacker forges administrative session cookies
  3. Attacker gains admin access to HFS instance
  4. Remote code execution on the underlying system follows

HFS is commonly used by small businesses, home users, and sometimes in corporate environments for quick file sharing. Many installations run with default configurations and may not receive timely updates.

Defense Strategies for HFS Deployments

  • Update immediately: Upgrade to the patched version of Rejetto HFS
  • Network segmentation: Ensure HFS instances are not directly exposed to the internet
  • Access controls: Implement strict firewall rules limiting who can reach HFS services
  • Consider alternatives: Evaluate whether HFS is the right tool or if enterprise file-sharing solutions would be more appropriate
  • Audit deployments: Many organizations have shadow IT file servers; scan for HFS instances across your network

The Broader Pattern: Exploit Velocity in 2026

These two vulnerabilities exemplify a troubling trend we've tracked throughout 2026: the time between vulnerability disclosure and active exploitation continues to compress. Attackers are faster, more organized, and increasingly effective at weaponizing new vulnerabilities.

Looking at CISA's recent KEV additions tells the story:

  • CVE-2026-88779 (Citrix NetScaler) — added October 4
  • CVE-2026-102490 and CVE-2026-102489 (Zammad) — added October 2
  • CVE-2026-104286 (Fortinet FortiMail) — added October 1
  • CVE-2026-76504 (Cisco Catalyst SD-WAN) — added September 30
  • CVE-2026-86950 (Apple products) — added September 29

Six actively exploited vulnerabilities added to the catalog in just six days. This pace demands a mature vulnerability management program with the ability to assess, prioritize, and patch critical systems rapidly.

Building Resilience Against Zero-Day Threats

While you can't predict which vulnerability will be exploited next, you can build organizational resilience:

Establish Patch SLAs

Define maximum time-to-patch windows for different severity levels. Critical vulnerabilities under active exploitation should trigger emergency change processes, not wait for the next maintenance window.

Implement Defense in Depth

No single control stops all attacks. Layer your defenses:

  • Network segmentation limits lateral movement
  • Web application firewalls can block some exploit attempts
  • Intrusion detection systems provide early warning
  • Endpoint detection and response catches post-exploitation activity

Monitor Authoritative Sources

CISA's KEV catalog, vendor security advisories, and threat intelligence feeds should trigger immediate action. Automate monitoring where possible and establish clear escalation procedures.

Practice Incident Response

When a critical zero-day drops, your team needs to execute flawlessly under pressure. Regular tabletop exercises and documented runbooks make the difference between controlled response and chaos.

Maintain Asset Inventory

You can't patch what you don't know you have. Maintain accurate inventory of all internet-facing assets, authentication infrastructure, and critical business systems.

Taking Action This Week

If you run Citrix NetScaler or Rejetto HFS in your environment, this week's priority is clear: patch immediately and verify the patches deployed successfully. For organizations without these specific products, use this as a forcing function to review your vulnerability management processes.

The exploit velocity we're seeing in 2026 rewards organizations with mature security operations and punishes those still treating patching as an afterthought.

If your organization needs help assessing exposure to these or other vulnerabilities, or you're looking to build a more resilient security posture through penetration testing and security assessments, reach out to our team to discuss how we can help.

Worried about the threats you just read about?

Vici Tech Solutions helps businesses across the US find and fix vulnerabilities before attackers do. Explore our penetration testing services or talk to us about your security posture.

Get a Security Assessment