// AI threat desk · 5 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCVECVSS 9.5 / 9.3 / 7.7

Citrix NetScaler flaw could cause denial of service

Citrix released emergency updates for a NetScaler denial-of-service vulnerability. HKCERT published its report on Oct 4, 2026.

AI-generated image of a technician inspecting network appliances in a dim server room.
AI-generated image, not a photo of the event.
Key takeaways
  • Citrix released emergency updates for a new NetScaler denial-of-service vulnerability.
  • HKCERT published its report on Oct 4, 2026.
  • SecurityWeek said Citrix’s advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

Citrix released emergency updates for a new NetScaler denial-of-service vulnerability, according to HKCERT.

NetScaler is a line of networking products owned by Cloud Software Group.

Citrix provides networking, virtualization, software-as-a-service and cloud-computing technologies. SecurityWeek said Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities exploited in the wild over the weekend.

On this page

Citrix advisory covered eight NetScaler vulnerabilities

SecurityWeek said the advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote-code-execution, HTTP request-smuggling, denial-of-service and security-bypass issues.

Citrix said the two zero-days for which it confirmed exploitation were tracked as CVE-2026-88771 and CVE-2026-88772.

SecurityWeek said CVE-2026-88771 was an unauthenticated remote-code-execution vulnerability affecting all NetScaler ADC and Gateway deployments, including default configurations. It said CVE-2026-88772 was a memory overflow that could enable remote code execution or denial-of-service attacks when DTLS was enabled.

VulnerabilityDetailCVSS
CVE-2026-88771Unauthenticated remote code execution affecting all NetScaler ADC and Gateway deployments, including default configurations9.5
CVE-2026-88772Memory overflow that could enable remote code execution or denial-of-service attacks when DTLS was enabled9.5

Check for compromise before patching

SecurityWeek reported that CISA warned threat actors were actively exploiting the vulnerabilities globally.

Citrix released emergency updates for the new denial-of-service vulnerability. SecurityWeek said the company’s advisory also covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

CISA encourages organizations to prioritize remediation of vulnerabilities in its Known Exploited Vulnerabilities catalog. It said these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

What to do now

  1. If possible, check for indication of compromise prior to patching.

FAQ

What happened to NetScaler?

Citrix released emergency updates for a new NetScaler denial-of-service vulnerability.

Which NetScaler products are covered by the advisory?

SecurityWeek said the advisory covered NetScaler ADC and NetScaler Gateway.

Which NetScaler vulnerabilities were confirmed exploited?

Citrix said the two zero-days for which it confirmed exploitation were tracked as CVE-2026-88771 and CVE-2026-88772.

How should administrators respond to the NetScaler vulnerabilities?

CISA urged users and administrators to review Citrix’s advisories and, if possible, check for indication of compromise prior to patching.

Sources

  1. Citrix patches NetScaler SAML zero-day exploited in attacks, HKCERTPrimary
  2. CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA, CISAPrimary
  3. Citrix patches NetScaler SAML zero-day exploited in attacks, BleepingComputer
  4. Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug, SecurityWeek
  5. Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities, Infosecurity Magazine
  6. Citrix Systems, Wikipedia
  7. NetScaler, Wikipedia
How we checked this story
ClaimSourceStatus
SecurityWeek said citrix’s advisory covered eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.SecurityWeekAttributed
The two zero-days Citrix confirmed as exploited were tracked as CVE-2026-88771 and CVE-2026-88772.Citrix, via SecurityWeekAttributed
SecurityWeek said cVE-2026-88771 is an unauthenticated remote-code-execution vulnerability affecting all NetScaler ADC and Gateway deployments, including default configurations.SecurityWeekAttributed
SecurityWeek said cVE-2026-88772 is a memory overflow exploitable for remote code execution or denial-of-service attacks on appliances with DTLS enabled.SecurityWeekAttributed
SecurityWeek said both zero-days have a CVSS score of 9.5.SecurityWeekAttributed
CISA said the vulnerabilities pose significant risks to the federal enterprise.CISAConfirmed
CISA encourages organizations to prioritize remediation of vulnerabilities in its Known Exploited Vulnerabilities catalog.CISAConfirmed
NetScaler is a line of networking products owned by Cloud Software Group.WikipediaConfirmed
Citrix provides virtualization, networking, software-as-a-service, and cloud-computing technologies.WikipediaConfirmed
Infosecurity Magazine said cVE-2026-3055 is a critical out-of-bounds read with a CVSS v4.0 severity score of 9.3.Infosecurity MagazineAttributed
Infosecurity Magazine said cVE-2026-4368 is a race condition flaw with a CVSS v4.0 severity score of 7.7.Infosecurity MagazineAttributed
HKCERT published its report on Oct 4, 2026.HKCERTConfirmed
CISA published its report on Sep 27, 2026.CISAConfirmed

Could not verify

  • How many NetScaler appliances or customers were affected is not established
  • How attackers exploited the vulnerability is not established
Explore with AI