Certainties in life: Death, taxes, and critical Citrix vulns under attack
Citrix says critical NetScaler flaws, including unauthenticated RCE, are under active global attack; CISA alerted defenders.
Citrix disclosed eight NetScaler vulnerabilities, including critical CVE-2026-88771 and CVE-2026-88772, both scored CVSS 9.5. CVE-2026-88771 lets an unauthenticated attacker execute arbitrary commands, while CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service. CVE-2026-88773, rated 9.3, allows HTTP request smuggling that can bypass front-end security controls, and additional bugs are rated 8.8 and 7.0. Citrix and CISA say the two critical flaws are already being exploited globally, and Citrix has issued OS refreshes with fixes.
- CVE-2026-88771 and CVE-2026-88772 are critical at CVSS 9.5 and already exploited.
- CVE-2026-88771 allows unauthenticated remote command execution on NetScaler.
- CVE-2026-88773, CVSS 9.3, enables HTTP request smuggling past front-end controls.
- CISA confirmed global exploitation and urged prioritized mitigation.
- Citrix has published OS refreshes that contain the fixes.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article455 words · extracted from theregister.com · click to collapse
security
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list.
On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – are rated critical with 9.5 CVSS scores.
CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service.
REG AD
A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure.
REG AD
Citrix has observed that both vulnerabilities are already under attack.
That sad fact saw the United States’ Cybersecurity and Infrastructure Security Agency on Sunday issue an alert because it too “has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.”
“Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities,” the alert adds.
Those risk management efforts will also have to consider a third critical vulnerability, the 9.3-rated CVE-2026-88773, allows HTTP request smuggling – an attack technique that can bypass security controls installed on front-end servers.
Three of the bugs are 8.8-rated memory overflow bugs that can make NetScaler appliances unstable. Another 8.8-rated bug relates to TCP Initial Sequence Number prediction, and there’s also a 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage.
Citrix’s post explains how to detect if your NetScaler needs a fix, and which patches to apply.
Thankfully, the company has already created OS refreshes that contain the fixes.
NetScaler is notoriously buggy. In March 2026, Citrix revealed critical vulns that were quickly attacked. The same thing happened in 2025, twice, and also in 2023.
REG AD
Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023.
Despite NetScaler’s long history of holes, some users choose not to patch the product. That’s fair enough, given that it’s not always easy to find a change window in which to install a patch. But it’s hard to explain given NetScaler is nearly always under attack, and security vendors’ increasing efforts to create compensating controls that make it possible to use flawed devices safely without patches. ®