AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 – Update 1

Canadian Centre for Cyber Security Version 2 imported change current

Imported from official source

Number: AL26-024Date: September 27, 2026Update: October 3, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. In response to the vendor security bulletin Footnote 1 and blog Footnote 2 released on September 27, 2026, the Cyber Centre is issuing this alert to raise awareness of the vulnerabilities and associated reports of active exploitation. Tracked as CVE-2026-88771 Footnote 3, this vulnerability is an Improper Input Validation vulnerability (CWE-20) Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance. Successful exploitation could result in complete compromise of the ap...

This version

Version
2 of 2
Recorded
October 03, 2026 21:00
Change
Imported change
Content hash
4e4906cf779e46f15f1f17516f4e0a44
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.