Subscribe Sign in

Certainties in life: Death, taxes, and Citrix vulns under attack

1 min read Rewritten in plain language

Security

Show what we removed
  • Death and taxes are said to be the only certainties in life.
  • On Sunday, the company published a bulletin warning of eight CVEs, the worst of which are rated critical with 9.5 CVSS scores.
  • A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure.
  • In March 2026, Citrix revealed vulns that were quickly attacked.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

Headline as published: Certainties in life: Death, taxes, and critical Citrix vulns under attack

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Sunday NetScaler patch dump fixes trio of vulns and five more serious messes.

Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered flaws in Citrix’s NetScaler application delivery controller and gateway products to that list.

On Sunday, the company published a bulletin warning of eight CVEs, the worst of which are rated critical with 9.5 CVSS scores.

CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service.

A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure.

Citrix has observed that both vulnerabilities are already under attack.

In March 2026, Citrix revealed vulns that were quickly attacked.

Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023.

Shortened to 1 minute of reading, this version reads 7.8 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 15 14 46 -0.6 21.2
Mundane Readneutralized from The Register 9.5 8 46 -0.4 21.3

Sign in to react.

This story is about a death. Comments are closed on those, because the people closest to it are among the people who read them. If something here is wrong, tell us — that we do read.