Certainties in life: Death, taxes, and critical Citrix vulns under attack
First reported by The Register ·
Your NetScaler appliances are actively being exploited by attackers, requiring immediate patching to prevent remote code execution.
Citrix has released emergency patches for its NetScaler application delivery controller and gateway products addressing eight vulnerabilities, three of which are critical and already under active exploitation. Two of the critical flaws, CVE-2026-88771 and CVE-2026-88772, carry CVSS scores of 9.5 and allow for remote code execution and memory overflow leading to RCE or denial of service, respectively. A third critical vulnerability, CVE-2026-88773 (9.3 CVSS), permits HTTP request smuggling to bypass security controls. The United States Cybersecurity and Infrastructure Security Agency (CISA) issued an alert confirming global exploitation of these vulnerabilities. Citrix's NetScaler has a history of critical vulnerabilities, with similar incidents occurring in March 2026, 2025, and 2023, and its flaws have appeared on the Five Eyes alliance's most-exploited bugs list from 2020 to 2023. Updating NetScaler appliances can be complex and may require downtime, prompting CISA to advise organizations to assess exposure and prioritize mitigation.
The widespread and active exploitation of critical vulnerabilities in NetScaler underscores a persistent challenge for organizations relying on legacy application delivery controllers. Despite numerous past disclosures and known patching complexities, attackers continue to find success, indicating a potential gap between vendor-issued fixes and timely user adoption. This situation highlights the ongoing tension between maintaining service availability and ensuring robust security, especially for critical infrastructure components that often demand scheduled downtime for updates.
The continuous targeting of NetScaler products suggests that organizations using these devices must adopt a more proactive security posture, including enhanced monitoring for exploitation attempts and potentially investing in compensating controls that can offer protection even when immediate patching is not feasible. The fact that a channel partner reportedly knew of the vulnerabilities before Citrix's official disclosure also raises questions about information dissemination and the speed at which critical security intelligence reaches end-users, potentially forcing CISA and other agencies to intervene with public alerts.
AI-written summary. May contain errors.