Skip to main content

Overview

Citrix has released a new security bulletin addressing multiple vulnerabilities, including two actively exploited, critical vulnerabilities for Citrix’s NetScaler ADC and Gateway. Through improper input validation (CVE-2026-88771) or memory overflow issues (CVE-2026-88772), successful exploitation of these vulnerabilities can enable remote code execution from an unauthenticated attacker in both cases. 

  • CVE-2026-88771 – Improper Input Validation Vulnerability – CVSSv4.0 Score: 9.5 
  • CVE-2026-88772 – Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability – CVSSv4.0 Score: 9.5 

Affected Versions:

  • NetScaler ADC and NetScaler Gateway: all versions before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway: all versions before 13.1-64.23
  • NetScaler ADC 14.1-FIPS: all versions before 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: all versions before 13.1.37.279

 

F5 has released a security advisory addressing a recent critical vulnerability that is currently being actively exploited. Successful exploitation of this vulnerability could lead to an unauthenticated adversary to perform remote code execution on the virtual server. 

  • CVE-2026-94127 – Heap-based Buffer Overflow Vulnerability – CVSSv4.0 Score: 9.3 

Affected Versions:

  • BIG-IP APM: 21.1.0
  • BIG-IP APM: 17.5.0 - 17.5.1
  • BIG-IP APML: 17.1.0 – 17.1.3

 

Check Point has released a security advisory documenting a recent, actively exploited vulnerability within the Check Point Management Server. Upon successfully exploiting the directory traversal and file upload vulnerability, enables an attacker to upload and execute arbitrary scripts. 

  • CVE-2026-93616 – Path Traversal Vulnerability – CVSSv3.1 Score: 9.8 

Affected Versions:

For both the Multi-Domain Security Management Server & Security Management Server:

  • R82.20
  • R82.10 Jumbo Hotfix Take 44 or lower
  • R82 Jumbo Hotfix Take 126 or lower
  • R81.20 Jumbo Hotfix Take 166 or lower
  • R81.10 Jumbo Hotfix Take 190 or lower [End of Service]
  • R80, R80.10, R80.20, R80.30, R80.40, R81 [All End of Service]

 

Recommended Action

Organisations are encouraged to review the appropriate security advisory pages and apply the updates:

Citrix: Citrix Security Bulletin 
 
F5: F5 Security Advisory 
 
Check Point: Check Point Security Advisory 

Topics

  • Advisory
  • Vulnerability
  • Exploit
  • Patches and Updates