Security News

Citrix NetScaler Under Attack Again: Critical Flaws Being Exploited Right Now

The Register · 28 Sept 2026
Key Takeaway If your business uses Citrix NetScaler, check Citrix's bulletin immediately and apply the available patches, since these flaws are already being actively exploited.

Citrix published a security bulletin revealing eight vulnerabilities affecting its NetScaler application delivery controller and gateway products. The two most severe, CVE-2026-88771 and CVE-2026-88772, carry a 9.5 severity rating out of 10. CVE-2026-88771 lets an unauthenticated attacker run arbitrary commands remotely, while CVE-2026-88772 is a memory overflow flaw that can trigger remote code execution or knock devices offline. Citrix has confirmed both are already being exploited, and a Reddit thread claims at least one Citrix partner was warning customers to take NetScalers offline a day before the official disclosure.

The US Cybersecurity and Infrastructure Security Agency has also issued an alert, saying it has received reports and threat intelligence confirming active global exploitation. A third critical bug, CVE-2026-88773 (rated 9.3), allows HTTP request smuggling, a technique that can sneak past security controls on front-end servers. The remaining five flaws range from 7.0 to 8.8 in severity and include memory overflow issues, an appliance instability bug, and a policy bypass problem.

Citrix has released updated software versions that fix all eight issues, and its bulletin explains how to check whether your appliance is vulnerable. This is not the first time NetScaler has faced this kind of attention: similar critical, actively exploited flaws were disclosed in March 2026, twice in 2025, and in 2023, making patching NetScaler an increasingly regular chore for IT teams.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.