Certainties in life: Death, taxes, and critical Citrix vulns under attack
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
Death, taxes, and now critical Citrix vulnerabilities are the unyielding certainties in life. On Sunday, Citrix issued a bulletin warning of eight CVEs, the most severe of which – CVE-2026-88771 and CVE-2026-88772 – are rated critical with 9.5 CVSS scores. The first vulnerability, CVE-2026-88771, allows remote code execution and can enable an unauthenticated attacker to run arbitrary commands. Meanwhile, CVE-2026-88772 is a memory overflow flaw that could lead to remote code execution or denial of service.
A Reddit thread suggests that at least one Citrix channel partner had knowledge of these flaws on Saturday and advised users to take their NetScalers offline – a day before Citrix disclosed the issue. Citrix confirmed that both vulnerabilities are already under attack. The United States’ Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on Sunday, noting that threat actors are actively exploiting these vulnerabilities globally.
CISA urged organizations to assess their exposure, prioritize mitigation, and account for these vulnerabilities in their risk-management strategies due to the complexity of updating Citrix NetScaler appliances, which may require downtime.
In addition to the eight critical vulnerabilities, a third critical flaw, CVE-2026-88773, rated 9.3, enables HTTP request smuggling, an attack technique used to bypass security controls installed on front-end servers. Three of the bugs are 8.8-rated memory overflow vulnerabilities that can destabilize NetScaler appliances. Another 8.8-rated vulnerability pertains to TCP Initial Sequence Number prediction, while there's also an 7.0-rated feature policy bypass resulting from improper HTTP URL-based expression usage.
Citrix’s guidance includes instructions on detecting if your NetScaler requires a fix and the necessary patches. The company has already developed OS refreshes containing the fixes. Despite Citrix's history of critical vulnerabilities, some users opt not to patch the product, primarily due to the difficulty in scheduling patches during maintenance windows.
However, the product is consistently under attack, and security vendors are working diligently to develop compensating controls that allow the use of flawed devices safely without patches.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.