Published on: 28 September 2026
Citrix has released security updates to address multiple vulnerabilities in several Citrix products or components. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Reports indicated that remote code execution vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are being exploited in the wild. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
For detailed information of the affected systems, please refer to the corresponding security advisories at vendor's website.
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service or security restriction bypass on an affected system.
Patches for affected systems are now available. Administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.