Citrix security advisory (AV26-965)
CISA added Citrix NetScaler ADC/Gateway flaws CVE-2026-88771 and CVE-2026-88772 to the KEV catalog; Canadian Cyber Centre urges immediate patching.
Canadian Centre for Cyber Security advisory AV26-965 (September 28, 2026) covers Citrix NetScaler ADC and Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-63.23, and affected FIPS/NDcPP builds. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities database on September 27, 2026, confirming active exploitation. Citrix's bulletin addresses eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778.
- CVE-2026-88771 and CVE-2026-88772 added to CISA KEV on September 27, 2026
- Affects NetScaler ADC/Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-63.23
- Citrix bulletin covers eight CVEs, CVE-2026-88771 through CVE-2026-88778
- FIPS and NDcPP builds also affected; apply updates as they become available
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article125 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-965
Date: September 28, 2026
As of September 27, 2026, Citrix is affected by vulnerabilities in the following products:
- NetScaler ADC and NetScaler Gateway 14.1
- Prior to 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1
- Prior to 13.1-63.23
- NetScaler ADC FIPS
- Prior to 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP
- Prior to 13.1-37.279
On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-965