AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 – Update 1

Imported from official source

Cybersecurity Classified by Officially

Number: AL26-024
Date: September 27, 2026
Update: October 3, 2026

This Alert is intended for IT professionals and managers.

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. In response to the vendor security bulletin Footnote 1 and blog Footnote 2 released on September 27, 2026, the Cyber Centre is issuing this alert to raise awareness of the vulnerabilities and associated reports of active exploitation.

Tracked as CVE-2026-88771 Footnote 3, this vulnerability is an Improper Input Validation vulnerability (CWE-20) Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance. Successful exploitation could result in complete compromise of the appliance, unauthorized access to applications and services, credential theft, lateral movement, and further compromise of internal systems.

Tracked as CVE-2026-88772 Footnote 5, this vulnerability is a Buffer Overflow vulnerability (CWE-119) Footnote 6. Successful exploitation may allow arbitrary code execution, memory corruption, denial of service conditions, or other unintended behaviour on affected appliances.

Reports indicate that these vulnerabilities are being exploited and have been observed across multiple Citrix customer environments worldwide, although the full extent of this activity remains unknown at this time.

This is an extract. The publication continues at the source.

Source: Canadian Centre for Cyber Security. Licence

Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772

Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on Titled: “AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772”

Provenance

Organization
Canadian Centre for Cyber Security — imported from official source
Official source
https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
Imported
September 27, 2026 20:00
Versions
2 recorded
Identity
https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-ci...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.