As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway
Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.
Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway
Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.
Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway
Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.
Why it matters: Organizations running customer-managed NetScaler ADC or Gateway systems must patch immediately, as CVE-2026-88771 and CVE-2026-88772 require no authentication and affect all deployments without special configuration.
- Source published
- First seen by Cybersecurity Tracker