Citrix / Cloud Software Group, NetScaler security bulletins and Security Updates blog
citrix-netscaler-security-bulletins · A · candidate
https://community.citrix.com/techzone-blogs/110_security-updates/
Added 2026-10-04: first-party PSIRT for NetScaler ADC and Gateway, the edge product with two exploited zero-day bulletins in a week (CTX697096 on 2026-09-27, CTX697174 on 2026-10-03). The store had no Citrix record, so the 2026-10-04 fire reached CTX697174 only through the ENISA EUVD API and a heise lead. Recipes verified by S1 and the main agent: `fetch_source.py feed https://community.citrix.com/rss/3-citrix-tech-zone-blogs.xml/ 10` returns dated items directly; `extract https://support.citrix.com/external/article/CTX<number>/...` reads a bulletin (affected/fixed tables, preconditions, revision history) on the direct transport; the community.citrix.com blog pages answer 403 to extract and WebFetch and are read through the reader. S1 recommends essential tier once promoted. Promote to active after 3 contributing runs.
Cited in 2 entries
Citation cadence
Citation days per ISO week (1 weeks of coverage span, total 2).
- CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)2026-10-04
- CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)2026-09-28