> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Certainties in life: Death, taxes, and critical Citrix vulns under attack

[SOURCE] The Register Security [DATE: 28/09/2026 06:49] [LANGUAGE: EN]
Certainties in life: Death, taxes, and critical Citrix vulns under attack
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – are rated critical with 9.5 CVSS scores. CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure. Citrix has observed that both vulnerabilities are already under attack. That sad fact saw the United States’ Cybersecurity and Infrastructure Security Agency on Sunday issue an alert because it too “has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.” “Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities,” the alert adds. Those risk management efforts will also have to consider a third critical vulnerability, the 9.3-rated CVE-2026-88773, allows HTTP request smuggling – an attack technique that can bypass security controls installed on front-end servers. Three of the bugs are 8.8-rated memory overflow bugs that can make NetScaler appliances unstable. Another 8.8-rated bug relates to TCP Initial Sequence Number prediction, and there’s also a 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage. Citrix’s post explains how to detect if your NetScaler needs a fix, and which patches to apply. Thankfully, the company has already created OS refreshes that contain the fixes. NetScaler is notoriously buggy. In March 2026, Citrix revealed critical vulns that were quickly attacked. The same thing happened in 2025, twice, and also in 2023. Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScaler’s long history of holes, some users choose not to patch the product. That’s fair enough, given that it’s not always easy to find a change window in which to install a patch. But it’s hard to explain given NetScaler is nearly always under attack, and security vendors’ increasing efforts to create compensating controls that make it possible to use flawed devices safely without patches. ®
[messages.read_original_source] →