AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
Imported from official source
Number: AL26-024Date: September 27, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. In response to the vendor security bulletin Footnote 1 and blog Footnote 2 released on September 27, 2026, the Cyber Centre is issuing this alert to raise awareness of the vulnerabilities and associated reports of active exploitation. Tracked as CVE-2026-88771 Footnote 3, this vulnerability is an Improper Input Validation vulnerability (CWE-20) Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance. Successful exploitation could result in complete compromise of the appliance, unauthorized a...
This version
- Version
- 1 of 2
- Recorded
- September 27, 2026 20:00
- Change
- Initial
- Content hash
c2d36eaf1b1042429b9362323faf7843- All versions
- Revision history