Skip to content
Citrix Releases Emergency Patch for Exploited NetScaler Vulnerability

Citrix Releases Emergency Patch for Exploited NetScaler Vulnerability

First seen 5 Oct 2026, 03:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 04:02 UTC
  • •CVE-2026-88779 is a high-risk denial-of-service vulnerability in Citrix NetScaler.
  • •Active exploitation has been confirmed, prompting Citrix to release emergency patches.
  • •Affected systems include NetScaler ADC and Gateway appliances configured for SAML authentication.

Citrix has issued emergency updates for a denial-of-service vulnerability in NetScaler, tracked as CVE-2026-88779, which is actively being exploited. The vulnerability, a memory buffer flaw, affects NetScaler ADC and Gateway appliances configured for SAML authentication. Citrix reported that targeted attacks have been observed, causing denial-of-service conditions on unmitigated deployments. The CVSS score for this vulnerability is 8.7, indicating a high risk. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28. Citrix has also provided Global Deny Lists to block known malicious IP addresses. Organizations are urged to apply the patches immediately to mitigate risks. Some administrators have reported unexpected reboots of their appliances, raising concerns about potential remote code execution capabilities of the flaw.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-06-25
CVE-2025-6543 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-88779 published
Citrix disclosed a denial-of-service vulnerability affecting NetScaler products, with active exploitation reported.
BleepingComputer
2026-10-04
Emergency patches released
Citrix released updates for NetScaler ADC and Gateway to address CVE-2026-88779, urging immediate installation.
BleepingComputer
2026-10-05
HKCERT issues advisory
HKCERT confirmed the vulnerability and advised users to apply the vendor's patches to mitigate risks.
Hkcert

More articles in this cluster (4)

Following this threat?

Track Citrix and CVE-2025-6543 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of NetScaler are affected?
NetScaler ADC and Gateway versions 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28 are affected.
Is there confirmed exploitation of this vulnerability?
Yes, active exploitation of CVE-2026-88779 has been confirmed by Citrix.
What should organizations do to protect themselves?
Organizations should immediately apply the emergency patches released by Citrix to mitigate the vulnerability.