- Citrix released emergency updates for a new NetScaler denial-of-service vulnerability.
- HKCERT published its report on Oct 4, 2026.
- SecurityWeek said Citrix’s advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
Citrix released emergency updates for a new NetScaler denial-of-service vulnerability, according to HKCERT.
NetScaler is a line of networking products owned by Cloud Software Group.
Citrix provides networking, virtualization, software-as-a-service and cloud-computing technologies. SecurityWeek said Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities exploited in the wild over the weekend.
On this page
Citrix advisory covered eight NetScaler vulnerabilities
SecurityWeek said the advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote-code-execution, HTTP request-smuggling, denial-of-service and security-bypass issues.
Citrix said the two zero-days for which it confirmed exploitation were tracked as CVE-2026-88771 and CVE-2026-88772.
SecurityWeek said CVE-2026-88771 was an unauthenticated remote-code-execution vulnerability affecting all NetScaler ADC and Gateway deployments, including default configurations. It said CVE-2026-88772 was a memory overflow that could enable remote code execution or denial-of-service attacks when DTLS was enabled.
| Vulnerability | Detail | CVSS |
|---|---|---|
| CVE-2026-88771 | Unauthenticated remote code execution affecting all NetScaler ADC and Gateway deployments, including default configurations | 9.5 |
| CVE-2026-88772 | Memory overflow that could enable remote code execution or denial-of-service attacks when DTLS was enabled | 9.5 |
Check for compromise before patching
SecurityWeek reported that CISA warned threat actors were actively exploiting the vulnerabilities globally.
Citrix released emergency updates for the new denial-of-service vulnerability. SecurityWeek said the company’s advisory also covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
CISA encourages organizations to prioritize remediation of vulnerabilities in its Known Exploited Vulnerabilities catalog. It said these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
What to do now
- If possible, check for indication of compromise prior to patching.
FAQ
What happened to NetScaler?
Citrix released emergency updates for a new NetScaler denial-of-service vulnerability.
Which NetScaler products are covered by the advisory?
SecurityWeek said the advisory covered NetScaler ADC and NetScaler Gateway.
Which NetScaler vulnerabilities were confirmed exploited?
Citrix said the two zero-days for which it confirmed exploitation were tracked as CVE-2026-88771 and CVE-2026-88772.
How should administrators respond to the NetScaler vulnerabilities?
CISA urged users and administrators to review Citrix’s advisories and, if possible, check for indication of compromise prior to patching.
Sources
- Citrix patches NetScaler SAML zero-day exploited in attacks, HKCERTPrimary
- CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA, CISAPrimary
- Citrix patches NetScaler SAML zero-day exploited in attacks, BleepingComputer
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug, SecurityWeek
- Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities, Infosecurity Magazine
- Citrix Systems, Wikipedia
- NetScaler, Wikipedia
How we checked this story
| Claim | Source | Status |
|---|---|---|
| SecurityWeek said citrix’s advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. | SecurityWeek | Attributed |
| The two zero-days Citrix confirmed as exploited were tracked as CVE-2026-88771 and CVE-2026-88772. | Citrix, via SecurityWeek | Attributed |
| SecurityWeek said cVE-2026-88771 is an unauthenticated remote-code-execution vulnerability affecting all NetScaler ADC and Gateway deployments, including default configurations. | SecurityWeek | Attributed |
| SecurityWeek said cVE-2026-88772 is a memory overflow exploitable for remote code execution or denial-of-service attacks on appliances with DTLS enabled. | SecurityWeek | Attributed |
| SecurityWeek said both zero-days have a CVSS score of 9.5. | SecurityWeek | Attributed |
| CISA said the vulnerabilities pose significant risks to the federal enterprise. | CISA | Confirmed |
| CISA encourages organizations to prioritize remediation of vulnerabilities in its Known Exploited Vulnerabilities catalog. | CISA | Confirmed |
| NetScaler is a line of networking products owned by Cloud Software Group. | Wikipedia | Confirmed |
| Citrix provides virtualization, networking, software-as-a-service, and cloud-computing technologies. | Wikipedia | Confirmed |
| Infosecurity Magazine said cVE-2026-3055 is a critical out-of-bounds read with a CVSS v4.0 severity score of 9.3. | Infosecurity Magazine | Attributed |
| Infosecurity Magazine said cVE-2026-4368 is a race condition flaw with a CVSS v4.0 severity score of 7.7. | Infosecurity Magazine | Attributed |
| HKCERT published its report on Oct 4, 2026. | HKCERT | Confirmed |
| CISA published its report on Sep 27, 2026. | CISA | Confirmed |
Could not verify
- How many NetScaler appliances or customers were affected is not established
- How attackers exploited the vulnerability is not established



