Citrix Issues Urgent Security Alerts Following Discovery of Eight New Vulnerabilities
On September 27, Citrix issued a pressing bulletin detailing updates for eight distinct vulnerabilities in its software products. Among these, two critical zero-day vulnerabilities have been found to be actively exploited in the wild. The flaws are associated with Citrix NetScaler ADC (formerly known as Citrix ADC) and Citrix NetScaler Gateway (previously Citrix Gateway). The vulnerabilities are graded based on their severity, with CVSS scores ranging from 7 to a concerning 9.5, highlighting the urgency and potential impact on affected users.
The two critical vulnerabilities that demand immediate attention are CVE-2026-88771 and CVE-2026-88772. The former is categorized as a remote code execution (RCE) flaw. It arises from inadequate input validation, which permits unauthenticated attackers to execute arbitrary commands within systems configured with default settings of NetScaler ADC and NetScaler Gateway. This flaw places all such deployments at serious risk of exploitation.
CVE-2026-88772 represents another significant risk, classifying as a memory overflow vulnerability that can lead to RCE or denial of service. This vulnerability specifically impacts any deployments where Datagram Transport Layer Security (DTLS) configuration is activated, which is the default setting on VPN vServers. Given these characteristics, the potential for widespread compromise is evident.
In a blog release, Citrix emphasized the immediate threat posed by these vulnerabilities, stating, "Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed." The company has strongly urged its customers to install the necessary patches as soon as possible to mitigate the risks associated with these vulnerabilities.
In addition to the two critical vulnerabilities, Citrix also pointed out CVE-2026-88773, a severe HTTP request smuggling flaw that is present when HTTP configuration is enabled on either NetScaler ADC or NetScaler Gateway, carrying a CVSS score of 9.3. The existence of this vulnerability adds further complexity to the security landscape for organizations relying on Citrix’s solutions.
Prior to Citrix’s announcement, reports surfaced indicating that the two zero-day vulnerabilities were already being exploited. On September 28, the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) responded by issuing a critical alert that urged organizations to patch their systems rapidly. Further reports indicated that the Dutch National Cyber Security Center (NCSC-NL) also circulated alerts to local organizations regarding these vulnerabilities, underlying the international concern due to the potential for abuse.
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) took added measures, mandating that federal agencies apply the necessary patches by September 30. While specific details surrounding the entities behind the exploitation attempts remain unclear, a concerning precedent was set in 2025 when the cyber intrusion group known as Salt Typhoon, reportedly linked to China, targeted another Citrix zero-day vulnerability, further illustrating the geopolitical dimensions of cybersecurity threats.
While the two critical vulnerabilities have garnered the majority of attention, Citrix’s bulletin also addressed five additional vulnerabilities, detailed as follows:
- CVE-2026-88774: A feature policy bypass caused by improper usage of HTTP URL-based expressions, with a CVSS rating of 7.
- CVE-2026-88775: Another memory overflow flaw leading to erratic behavior or a denial of service, assigned a CVSS score of 8.8.
- CVE-2026-88776: Similarly categorized as a memory overflow vulnerability, also leading to unpredictable behavior or denial of service, with a CVSS rating of 8.8.
- CVE-2026-88777: This vulnerability pertains to memory overflow, with consequences including erratic system behavior, rated at 8.8.
- CVE-2026-88778: A TCP Initial Sequence Number (ISN) prediction flaw, carrying a CVSS score of 8.8.
Citrix clarified that the vulnerabilities are relevant only to customer-managed instances of Citrix NetScaler ADC and Citrix NetScaler Gateway. For users of Citrix-managed cloud services and Adaptive Authentication, the Cloud Software Group is responsible for applying the necessary updates, ensuring that customers are safeguarded against these newly identified threats.
In light of these developments, organizations utilizing Citrix products are strongly encouraged to act swiftly in patching their systems to protect against these vulnerabilities, further underscoring the ongoing challenges in the realm of cybersecurity.
