Ethical Hacking News
Critical vulnerabilities have been identified in Citrix's NetScaler application delivery controller and gateway products, with two of them already under active attack. The vulnerabilities, including three critical ones, have left organizations scrambling to patch their systems before they can be exploited.
Citrix has identified eight CVEs, including three critical ones, with two already under active attack. The critical vulnerabilities have a high severity rating, with two allowing remote code execution and one allowing HTTP request smuggling. Five more serious memory overflow bugs have been identified, including one related to TCP Initial Sequence Number prediction. Citrix's products have a history of security issues, consistently ranked among the most-exploited bugs from 2020 to 2023. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert urging organizations to assess their exposure and prioritize mitigation. Citrix has released OS refreshes with fixes for the identified vulnerabilities, but advises users to detect if their NetScaler needs a fix. The patching process is under scrutiny, with some arguing it's not keeping pace with the rapid pace of vulnerability discovery.
Citrix, a leading provider of application delivery controller and gateway products, has recently faced a barrage of critical vulnerabilities that have left many organizations scrambling to patch their systems before they can be exploited. In a worrying turn of events, the company has confirmed that eight CVEs, including three critical ones, have been identified, with two of them already under active attack.
The critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have been rated with a 9.5 CVSS (Common Vulnerability Scoring System) score, indicating a high level of severity. CVE-2026-88771 allows for remote code execution, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. The third critical vulnerability, CVE-2026-88773, is rated at 9.3 and allows HTTP request smuggling, which can bypass security controls installed on front-end servers.
In addition to these critical vulnerabilities, five more serious memory overflow bugs have been identified, including one related to TCP Initial Sequence Number prediction. The severity of these vulnerabilities is rated at 8.8, indicating a significant risk to the security of the affected systems.
The news of these vulnerabilities comes as no surprise to some, as Citrix's NetScaler product has a history of being plagued by bugs and security issues. In fact, the company's products have been consistently ranked among the most-exploited bugs in the annual list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023.
Despite the risks, some users may choose not to patch their NetScaler products, citing the challenges of finding a suitable change window for installation. However, this approach is fraught with danger, as Citrix's products are nearly always under attack, and security vendors' efforts to create compensating controls to make it possible to use flawed devices safely without patches have been increasingly effective.
In response to the growing threat, the United States' Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert, urging organizations to assess their exposure, prioritize mitigation, and account for these vulnerabilities in their risk-management activities. The agency's warning comes as the first reports and partner threat intelligence have confirmed that threat actors are actively exploiting these vulnerabilities globally.
Citrix has taken steps to address the issue by releasing OS refreshes that contain the fixes for the identified vulnerabilities. However, the company's post on the matter advises users to detect if their NetScaler needs a fix and which patches to apply. This approach acknowledges the complexity and potential downtime associated with patching Citrix products and seeks to minimize the disruption to users.
The flood of critical vulnerabilities has also led to increased scrutiny of the patching process, with some arguing that the current approach is not keeping pace with the rapid pace of vulnerability discovery. Canonical, the developer of Ubuntu, has acknowledged this issue and is working to increase the frequency of its kernel releases to address the growing number of vulnerabilities.
The impact of these vulnerabilities extends beyond the realm of cybersecurity, as organizations grapple with the practicalities of patching their systems and minimizing downtime. The situation serves as a stark reminder of the importance of proactive security measures and the need for organizations to stay vigilant in the face of emerging threats.
In conclusion, the critical Citrix vulnerabilities under attack serve as a stark reminder of the importance of proactive security measures and the need for organizations to stay vigilant in the face of emerging threats. As organizations continue to navigate the complex landscape of cybersecurity, it is essential that they prioritize patching and take proactive steps to mitigate the risks associated with these vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Citrix-Vulnerabilities-Under-Attack-The-Patching-Conundrum-ehn.shtml
https://www.theregister.com/security/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack/5299369
Published: Mon Sep 28 02:05:33 2026 by llama3.2 3B Q4_K_M