Site icon VMVirtualMachine.com

Cyber authorities issue alerts over exploitation of Citrix vulns | Computer Weekly

Cyber authorities issue alerts over exploitation of Citrix vulns | Computer Weekly

By Alex Scroxton
Publication Date: 2026-09-29 11:40:00

Two distinct remote zero-day vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Gateway are coming under rapid exploitation from threat actors, prompting fresh alerts from government cyber agencies in the UK, the Netherlands, and the US.

The flaws in the frequently–targeted NetScaler product set, which run access, load balancing and authentication at the network edge, are among a tranche of fixes released by Citrix on Sunday 27 September, and should be patched immediately.

The core issues in scope are flaws tracked as CVE-2026-88771, which arises from improper input validation and enables an unauthenticated actor to execute arbitrary commands, and CVE-2026-88772, which arises from a memory overflow condition and enables both denial-of-service or remote code execution (RCE) attacks.

The issues affect versions 13.1 and 14.1 of NetScaler ADC and Gateway prior to 13.1-64.23 and 14.1-73.37 respectively, NetScaler ADC FIPS prior to version 14.1-73/37…

Exit mobile version