{
  "id": 10394281,
  "title": "Certainties in life: Death, taxes, and critical Citrix vulns under attack",
  "url": "https://urgent.news/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack-10394281",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T06:49:03.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack/5299369"
  },
  "original_language": "en",
  "account": "As the adage goes, death and taxes are the only certainties in life. However, a new certainty may soon join them: attackers targeting critical vulnerabilities in Citrix's NetScaler application delivery controller and gateway products. On Sunday, Citrix issued a bulletin warning of eight CVEs, with the worst two rated critical, boasting 9.5 CVSS scores. The first, CVE-2026-88771, enables remote code execution and allows an unauthenticated attacker to run arbitrary commands. The second, CVE-2026-88772, is a memory overflow vulnerability that could result in remote code execution or denial of service. A Reddit thread alleges that at least one Citrix channel partner knew about these flaws on Saturday and advised users to take their NetScalers offline—the day before Citrix's disclosure. In response, the United States' Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on Sunday, noting that threat actors are actively exploiting these vulnerabilities globally. CISA advises organizations to assess their exposure, prioritize mitigation, and incorporate these vulnerabilities into their risk-management activities.\n\nCitrix has observed that both vulnerabilities are already under attack. Mitigating these risks may require organizations to consider a third critical vulnerability, CVE-2026-88773, which has a 9.3 rating and allows HTTP request smuggling, potentially bypassing security controls on front-end servers. Three of these issues are 8.8-rated memory overflow bugs that can destabilize NetScaler appliances, while another 8.8-rated bug stems from TCP Initial Sequence Number prediction. Additionally, there's an 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage.\n\nCitrix's guidance outlines how users can determine if their NetScalers need updating and which patches to apply. Fortunately, the company has already developed OS refreshes containing these fixes. NetScaler has a reputation for being riddled with bugs. In March 2026, Citrix disclosed other critical vulnerabilities, which were rapidly exploited. This pattern repeated in 2025 (twice) and in 2023. Citrix's NetScaler features consistently rank among the most-exploited bugs listed by cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScaler's history of security flaws, some users still avoid applying patches. This decision may be understandable, given the challenge of scheduling patch installations. However, given NetScaler's persistent vulnerability exposure and security vendors' efforts to create compensating controls that allow flawed devices to operate safely without patches, the reasoning behind skipping patches becomes harder to justify.",
  "summary": "Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Certainties in life: Death, taxes, and critical Citrix vulns under attack",
        "url": "https://urgent.news/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack",
        "published": "2026-09-28T06:49:03.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}