CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8668

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.

Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.

Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.

Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary