Certainties in life: Death, taxes, and critical Citrix vulns under attack
Citrix has released urgent patches for eight vulnerabilities in its NetScaler products, including two critical flaws that are already being actively exploited by threat actors. The US Cybersecurity and Infrastructure Security Agency issued an alert urging organizations to prioritize mitigation due to the complexity of updating these appliances. This incident follows a recurring pattern of severe security breaches in NetScaler, which has been a frequent target for attackers in recent years.
- ▪Citrix disclosed eight CVEs, with CVE-2026-88771 and CVE-2026-88772 rated as critical with 9.5 CVSS scores.
- ▪CISA confirmed that threat actors are actively exploiting these vulnerabilities globally, prompting an immediate security alert.
- ▪A third critical vulnerability, CVE-2026-88773, allows for HTTP request smuggling that can bypass front-end security controls.
- ▪Reports suggest a Citrix channel partner warned users to take NetScalers offline a day before the official disclosure.
- ▪NetScaler has a history of being targeted, appearing on the Five Eyes alliance's most-exploited bugs list from 2020 to 2023.
The Register publishes from United Kingdom and files mainly under tech. We currently carry 732 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | www.theregister.com - Articles |
| Canonical URL | https://www.theregister.com/security/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack/5299369 |
| Publication time | Mon, 28 Sep 2026 08:49:03 +0200 |
| Retrieval time | 2026-09-28T07:21:07.047Z |
| Last seen | 2026-09-28T07:21:07.047Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | 3Pdo8fMMh1Gw · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
(function() { let windowUrl = window.location.href; windowUrl = windowUrl.substring(windowUrl.indexOf('?') + 1); let messageElement = document.querySelector('.shareableMessage'); if (windowUrl && windowUrl.includes('code') && windowUrl.includes('expires')) { messageElement.style.display = 'block'; } })(); security Certainties in life: Death, taxes, and critical Citrix vulns under attack Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes Simon Sharwood Simon Sharwood APAC Editor Published mon 28 Sep 2026 // 07:49 UTC READ MORE CVE flood pushes Ubuntu onto weekly kernel release cycle 3 days ago Mythos has made 2026 patching hell.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at www.theregister.com - Articles.