Urgent.News

What's breaking now, across thousands of outlets.

Tech

Certainties in life: Death, taxes, and critical Citrix vulns under attack

Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes

Certainties in life: Death, taxes, and critical Citrix vulns under attack

As the adage goes, death and taxes are the only certainties in life. However, a new certainty may soon join them: attackers targeting critical vulnerabilities in Citrix's NetScaler application delivery controller and gateway products. On Sunday, Citrix issued a bulletin warning of eight CVEs, with the worst two rated critical, boasting 9.5 CVSS scores.

The first, CVE-2026-88771, enables remote code execution and allows an unauthenticated attacker to run arbitrary commands. The second, CVE-2026-88772, is a memory overflow vulnerability that could result in remote code execution or denial of service. A Reddit thread alleges that at least one Citrix channel partner knew about these flaws on Saturday and advised users to take their NetScalers offline—the day before Citrix's disclosure.

In response, the United States' Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on Sunday, noting that threat actors are actively exploiting these vulnerabilities globally. CISA advises organizations to assess their exposure, prioritize mitigation, and incorporate these vulnerabilities into their risk-management activities.

Citrix has observed that both vulnerabilities are already under attack. Mitigating these risks may require organizations to consider a third critical vulnerability, CVE-2026-88773, which has a 9.3 rating and allows HTTP request smuggling, potentially bypassing security controls on front-end servers. Three of these issues are 8.8-rated memory overflow bugs that can destabilize NetScaler appliances, while another 8.8-rated bug stems from TCP Initial Sequence Number prediction.

Additionally, there's an 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage.

Citrix's guidance outlines how users can determine if their NetScalers need updating and which patches to apply. Fortunately, the company has already developed OS refreshes containing these fixes. NetScaler has a reputation for being riddled with bugs. In March 2026, Citrix disclosed other critical vulnerabilities, which were rapidly exploited.

This pattern repeated in 2025 (twice) and in 2023. Citrix's NetScaler features consistently rank among the most-exploited bugs listed by cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScaler's history of security flaws, some users still avoid applying patches. This decision may be understandable, given the challenge of scheduling patch installations.

However, given NetScaler's persistent vulnerability exposure and security vendors' efforts to create compensating controls that allow flawed devices to operate safely without patches, the reasoning behind skipping patches becomes harder to justify.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

LS ELECTRIC Showcases Data Center Power Solutions

LS ELECTRIC announced that it will participate in ‘Data Centre World Asia 2026’ held at the Marina Bay Sands Expo and Convention Centre in Singapore for two days starting on Sep. 29.

  • LS ELECTRIC to exhibit data center power solutions at Data Centre World Asia 2026 in Singapore
  • Company showcases Ready Power Infrastructure, Customized Solutions for data centers
  • Focus on efficient on-site installation, low-voltage switchboards, and BESS for eco-friendly backup

New Flyover Inaugurated in Karachi

Sindh Senior Minister for Information and Transport and Mass Transit Sharjeel Inam Memon inaugurated the Mosamiyat Flyover on Sunday as … Read More The post New Flyover Inaugurated in Karachi appeared…

More from Monday 28 September →