Hkcert Citrix Releases Emergency Patch for Exploited NetScaler Vulnerability
Article Content
- •CVE-2026-88779 is a high-risk denial-of-service vulnerability in Citrix NetScaler.
- •Active exploitation has been confirmed, prompting Citrix to release emergency patches.
- •Affected systems include NetScaler ADC and Gateway appliances configured for SAML authentication.
Citrix has issued emergency updates for a denial-of-service vulnerability in NetScaler, tracked as CVE-2026-88779, which is actively being exploited. The vulnerability, a memory buffer flaw, affects NetScaler ADC and Gateway appliances configured for SAML authentication. Citrix reported that targeted attacks have been observed, causing denial-of-service conditions on unmitigated deployments. The CVSS score for this vulnerability is 8.7, indicating a high risk. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28. Citrix has also provided Global Deny Lists to block known malicious IP addresses. Organizations are urged to apply the patches immediately to mitigate risks. Some administrators have reported unexpected reboots of their appliances, raising concerns about potential remote code execution capabilities of the flaw.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Citrix and CVE-2025-6543 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of NetScaler are affected?
Is there confirmed exploitation of this vulnerability?
What should organizations do to protect themselves?
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…