citrix
2 TopicsFAQ about CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Zero-Day RCE vulnerabilities
On September 27, Citrix published a security bulletin for two NetScaler ADC and NetScaler Gateway vulnerabilities that were exploited against unpatched customer deployments. CVE Description CVSSv4 CVE-2026-88771 Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation vulnerability 9.5 CVE-2026-88772 Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability 9.5 CVE-2026-88771 affects all deployments with no additional configuration required. CVE-2026-88772 requires DTLS to be enabled, which is the default on VPN virtual servers. Both have been classified as Vulnerabilities of Interest as part of Tenable's Vulnerability Watch. For more information about these vulnerabilities, including patch versions, IoC guidance, and Tenable product coverage, please visit our blog.525Views0likes0CommentsCitrix Patches Zero Day in ADC and Gateway CVE-2022-27518...
Citrix Patches Zero Day in ADC and Gateway CVE-2022-27518 On December 13, Citrix published an advisory for a vulnerability affecting several versions of Gateway and Application Delivery Controller products. Threat actors have been exploiting the vulnerability. CVE-2022-27518 is an unauthenticated remote code execution vulnerability in several versions of Citrix ADC and Citrix Gateway. Affected devices are vulnerable when configured as a SAML (Security Assertion Markup Language service provider (SP) or Identity Provider (IdP). For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.16Views0likes0Comments