Citrix Products Multiple Vulnerabilities

Imported from official source

Announcement

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.

CVE-2026-88771 and CVE-2026-88772 are being exploited in the wild. CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Hence, the risk level is rated as Extremely High Risk.

  • NetScaler ADC and  NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • NetScaler ADC and  NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
  • Before installation of the software, please visit the vendor web-site for more details.

    Ubuntu Linux Kernel Multiple Vulnerabilities

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928

    Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
    Official source
    https://www.hkcert.org/getrss/security-bulletin RSS
    Imported
    October 03, 2026 20:41
    Versions
    1 recorded
    Identity
    https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.