Urgent.News

What's breaking now, across thousands of outlets.

Tech

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed Citrix published fixes for two NetScaler flaws on 2026-09-27 after watchTowr reported unpatched remote code execution bugs under active exploitation. Both flaws are rated 9.5 under CVSS v4. The two vulnerabilities CVE-2026-88771 is improper input validation that lets an unauthenticated attacker…

Two critical vulnerabilities were discovered in Citrix NetScaler, a network security appliance. Citrix released patches on September 27, 2026, after reports of unpatched remote code execution bugs were found active. Both vulnerabilities are rated 9.5 on the CVSS v4 scale. The first flaw, CVE-2026-88771, is due to improper input validation that allows an unauthenticated attacker to execute arbitrary commands.

The second vulnerability, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service. The latter affects appliances with DTLS enabled, which is enabled by default for VPN virtual servers. This means NetScaler Gateway appliances are affected unless DTLS is explicitly disabled. Citrix did not confirm whether the vulnerabilities match the ones reported by watchTowr, but they align with the account.

Administrators on the Citrix forum were advised to shut down NetScalers immediately. Exploits of these vulnerabilities have been observed on unmitigated deployments, but the extent of the exploitation, the perpetrators, and the timeline are unknown. The affected versions include 14.1-73.32, 13.1-63.21, and subsequent builds that fixed the August authentication bypass vulnerability.

The fixes are available for NetScaler ADC and NetScaler Gateway versions 14.1-73.37 and later, 13.1-64.23 and later, and 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later. Citrix recommends preserving authentication and VPN logs before applying the patches and investigating for anomalous command execution and outbound connections.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Log Collector & Dashboard for Elixir.

A Simple Log Collector for Elixir I’ve just released a small log collection stack for Elixir applications. The idea is simple: store application logs in ClickHouse and provide a lightweight dashboard…

  • Elixir developer creates log collection system
  • Uses ClickHouse for fast log storage and querying
  • Dashboard offers search and filtering features

Second October 'event' possible with new Macs as the focus

Apple already has an unannounced product reveal expected on October 13 and rumors suggest a second round of releases could occur by the end of the month. New MacBook Pro models are expected soon It is gearing up to be a very busy October for Apple, as iPhone Duo ships, Apple Home gets several new products , and now a possible new Mac…

More from Tuesday 6 October →