Vendor

Citrix (Cloud Software Group)

Citrix (Cloud Software Group) news

Severity: ElevatedAction: Be aware

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

CISA added CVE-2026-88779 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on October 4, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: HighAction: ReviewExploitation: Suspected

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88772 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on September 27, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771 , CVE-2026-88772 , CVE-2026-88773 , CVE-2026-88774 , CVE-2026-88775 , CVE-2026-88776 , CVE-2026-88777 , and CVE-2026-88778 . CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog . Both are critical, zero-day…

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Coverage

    US, Australia warn of latest Citrix vulnerability after NetScaler advisory

    Basis: Reporting by The Record by Recorded Future News

  2. Severity raisedUpdateKEV

    UPDATE: severity raised to critical: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  3. AdvisoryKEV

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  4. Added to CISA KEVCVE-2026-88779

    CVE-2026-88779 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

  5. Coverage

    Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    Basis: Reporting by Dark Reading

  6. Coverage

    US, UK warn of exploited Citrix NetScaler zero-day bugs

    Basis: Reporting by The Record by Recorded Future News

  7. Added to CISA KEVCVE-2026-88772

    CVE-2026-88772 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

  8. Added to CISA KEVCVE-2026-88771

    CVE-2026-88771 added to CISA KEV: Citrix NetScaler, Citrix NetScaler Improper Input Validation Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited

All 27 →

Citrix NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Added Oct 4, 2026Fed. due Oct 7, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Improper Input Validation Vulnerability

Added Sep 27, 2026Fed. due Sep 30, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Added Sep 27, 2026Fed. due Sep 30, 2026Coverage →

Citrix NetScaler

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Added Sep 9, 2026Fed. due Sep 12, 2026

Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Added Aug 26, 2026Fed. due Aug 29, 2026

Citrix NetScaler

Citrix NetScaler Out-of-Bounds Read Vulnerability

Added Mar 30, 2026Fed. due Apr 2, 2026

Citrix NetScaler

Citrix NetScaler Memory Overflow Vulnerability

Added Aug 26, 2025Fed. due Aug 28, 2025

Citrix Session Recording

Citrix Session Recording Improper Privilege Management Vulnerability

Added Aug 25, 2025Fed. due Sep 15, 2025

Citrix Session Recording

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Added Aug 25, 2025Fed. due Sep 15, 2025
CVE-2025-5777RansomwareCVSS 9.3

Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Added Jul 10, 2025Fed. due Jul 11, 2025

Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

Added Jun 30, 2025Fed. due Jul 21, 2025

Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Added Jan 17, 2024Fed. due Jan 24, 2024

Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Added Jan 17, 2024Fed. due Feb 7, 2024
CVE-2023-4966RansomwareCVSS 7.5

Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Added Oct 18, 2023Fed. due Nov 8, 2023

Citrix Content Collaboration

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Added Aug 16, 2023Fed. due Sep 6, 2023
CVE-2023-3519RansomwareCVSS 9.8

Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Added Jul 19, 2023Fed. due Aug 9, 2023

Citrix Application Delivery Controller (ADC) and Gateway

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Added Dec 13, 2022Fed. due Jan 3, 2023

Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server

Citrix Multiple Products Remote Code Execution Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022

Citrix SD-WAN and NetScaler

Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022
CVE-2021-22941RansomwareCVSS 9.8

Citrix ShareFile

Citrix ShareFile Improper Access Control Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022

Products