NetScaler attacks force service shutdowns across critical sectors

NetScaler attacks force service shutdowns across critical sectors. Organizations across North America and Europe are disrupting services as they respond to attacks against NetScaler remote-access infrastructure.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, October 1st, 2026.

Organizations across North America and Europe are disrupting services as they respond to attacks against NetScaler remote-access infrastructure. Two critical weaknesses are under active exploitation and have been added to CISA’s Known Exploited Vulnerabilities catalog. Reporting identified at least 78 targeted organizations, and more than twenty thousand exposed instances were potentially vulnerable. Some Dutch hospitals suspended online patient portal access after taking affected systems offline.

The risk extends beyond the appliance itself. These gateways sit at the network edge and can provide a path toward credentials, applications, and internal systems. Patching is urgent, but it may not remove access that attackers established before the update, and it doesn’t address credentials they may already have stolen. Leaders should prepare for containment steps that could interrupt remote work, clinical access, or customer services. Defenders should investigate for web shells, tunneling activity, configuration changes, unusual crashes, and compromised sessions. This is another reminder that edge systems are attractive because they’re exposed to the internet and may sit outside normal endpoint monitoring. Patch immediately, isolate suspected appliances, hunt for persistence, and rotate exposed credentials after containment.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

NetScaler attacks force service shutdowns across critical sectors
Broadcast by