Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Why this matters
The CSSF alert addresses multiple critical vulnerabilities in Citrix NetScaler products with active in-the-wild exploitation. Two CVEs enable unauthenticated remote code execution, which the CSSF explicitly classifies as a major ICT-related incident requiring notification under DORA (Circular 25/893) or legacy framework (Circular 24/847). This creates a direct regulatory obligation for affected firms. The advisory applies across banking, insurance, and investment sectors that rely on NetScaler for network security. Urgency is critical due to active exploitation and mandatory reporting obligations.
AI-generated classification rationale, not a full analysis. Verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
Published by CSSF . Read the full notice at the source for the authoritative text.
Context
Commission de Surveillance du Secteur Financier (CSSF) — Luxembourg financial regulator. We track 600 updates from them.
Luxembourg's CSSF regulates the investment fund industry. Browse all Luxembourg updates.
This update is classified under Technology & Cyber, Operational Resilience / Outsourcing and Banking & Credit.