AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 – Update 1
Cybersecurity Classified by Officially
Number: AL26-024
Date: September 27, 2026
Update: October 3, 2026
This Alert is intended for IT professionals and managers.
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. In response to the vendor security bulletin Footnote 1 and blog Footnote 2 released on September 27, 2026, the Cyber Centre is issuing this alert to raise awareness of the vulnerabilities and associated reports of active exploitation.
Tracked as CVE-2026-88771 Footnote 3, this vulnerability is an Improper Input Validation vulnerability (CWE-20) Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance. Successful exploitation could result in complete compromise of the appliance, unauthorized access to applications and services, credential theft, lateral movement, and further compromise of internal systems.
Tracked as CVE-2026-88772 Footnote 5, this vulnerability is a Buffer Overflow vulnerability (CWE-119) Footnote 6. Successful exploitation may allow arbitrary code execution, memory corruption, denial of service conditions, or other unintended behaviour on affected appliances.
Reports indicate that these vulnerabilities are being exploited and have been observed across multiple Citrix customer environments worldwide, although the full extent of this activity remains unknown at this time.
This is an extract. The publication continues at the source.
Source: Canadian Centre for Cyber Security. Licence
Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on Titled: “AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772”
Provenance
- Organization
- Canadian Centre for Cyber Security — imported from official source
- Official source
- https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
- Imported
- September 27, 2026 20:00
- Versions
- 2 recorded
- Identity
-
https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-ci...