Citrix Products Multiple Vulnerabilities
Release Date: 28 Sep 2026
Multiple vulnerabilities were identified in Citrix Products.
A remote attacker could exploit some of these vulnerabilities to trigger denial
of service condition, security restriction bypass, sensitive information
disclosure and remote code execution on the targeted system.
Note:
CVE-2026-88771 and CVE-2026-88772 are being exploited
in the wild. CVE-2026-88771 is an improper input validation vulnerability in
Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated
attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow
vulnerability that can lead to remote code execution or denial of service.
Hence, the risk level is rated as Extremely High Risk.
Impact
- Denial
of Service
- Remote
Code Execution
- Information
Disclosure
- Security
Restriction Bypass
System / Technologies affected
- NetScaler
ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.37
- NetScaler
ADC and NetScaler Gateway 13.1 BEFORE 13.1-64.23
- NetScaler
ADC FIPS BEFORE 14.1-73.37 FIPS
- NetScaler
ADC FIPS and NDcPP BEFORE 13.1-37.279
Solutions
Before installation of the software, please visit the
vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2026-88771
- CVE-2026-88772
- CVE-2026-88773
- CVE-2026-88774
- CVE-2026-88775
- CVE-2026-88776
- CVE-2026-88777
- CVE-2026-88778
Source
Related Link
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
沒有留言:
發佈留言