Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772)
Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments.
Lead issues (vendor CVSS v4 Base Score 9.5 each):
• CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required).
• CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF).
Fixed builds (install ASAP):
• NetScaler ADC / Gateway 14.1-73.37 and later
• NetScaler ADC / Gateway 13.1-64.23 and later (13.1)
• NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
• NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later
Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction).
⚠️ Analyst Note:
This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes).
Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise.
CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media.
Official Citrix bulletin (CTX697096):
https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html
#Citrix#NetScaler#ZeroDay#RCE#CVE202688771#CVE202688772#Vulnerability#CyberSecurity#ThreatIntel#DDW
Citrix-file 2, the revenge?
In 2020 ontstond in Nederland een nieuw woord: de citrix-file. Het verwees naar de Citrix software die heel wat ambtenaren gebruikten om veilig van thuis te werken. In Citrix werd toen een zware, makkelijk uit te buiten bug ontdekt, CVE 2019 19781, door de industrie Shitrix genoemd. Snoodaards konden daarmee zonder inloggegevens een heel systeem overnemen. De Nederlandse overheid panikeerde, verbood thuiswerk en het gevolg was een reeks ellenlange files op de snelweg.
Vandaag is er misschien een nieuwe citrixfile in de maak. Er zitten opnieuw meerdere ernstige fouten in NetScaler, waarvan twee met een kritieke status en een score van ( CVE-2026-88771 en 2) , samen met nog zes andere lekken CVE-2026-88773 t.e.m 8) .
Het verontrustende is dat er al langer geruchten gaan dat deze exploits al actief in het wild gebruikt worden. Hackers gebruiken het volgens NTSC actief om webshells te gaan installeren.
Citrix immers de gebruiksvriendelijke voordeur van je infrastructuur.
Voor wie deze software draait en rechtstreeks aan het internet heeft hangen, wacht er dus meer werk dan enkel de patches installeren. De kans is reëel dat aanvallers al binnen zitten. Het loont om grondig te controleren of er al misbruik is gemaakt voor je update. Ga actief op zoek naar sporen van inbraak ( Indicators of Compromise), er zijn intussen detectietools beschikbaar. Neem meteen ook de tijd om alle logs dubbel te controleren en sleutels en wachtwoorden te roteren.
Veel sterkte en aan de arbeid.
En misschien moeten jullie dan maar eens nadenken of we Netscaler niet door een veiliger alternatief kunnen vervangen. Misschien loont het om af en toe een ezel te zijn.
Meer documentatie, tools, bronnen en vooruitschrijdende inzichten vind je in de comments hieronder: 👇
https://www.linkedin.com/posts/janguldentops_citrix-file-2-the-revenge-in-2020-ontstond-activity-7510207956261638144-EhhI