Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited
Cloud Software Group has disclosed multiple vulnerabilities in its NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products. The security advisory published on September 27, 2026, details eight CVEs that include risks of remote code execution, denial of service, and HTTP request smuggling.
The company rated the overall advisory as Critical. Two vulnerabilities stand out because active exploitation has already been confirmed: CVE-2026-88771 and CVE-2026-88772.
CVE-2026-88771 is caused by improper input validation. It permits unauthenticated attackers to execute arbitrary commands. Every affected environment, including default configurations, is impacted.
CVE-2026-88772 results from a memory overflow condition. Successful exploitation can lead to arbitrary code execution or a denial-of-service condition. The flaw affects systems where Datagram Transport Layer Security (DTLS) is enabled. Because DTLS is enabled by default on VPN vServer instances, a wide range of deployments require immediate attention.
Security teams should review the official bulletins CTX697096 and the NetScaler Security Bulletin for CVE-2026-88771 through CVE-2026-88778, apply available patches without delay, and conduct forensic investigations for signs of prior compromise.
Related articles
Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic
A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.
YApi Abandoned Since 2022: Fork Yapix Exposes Forgable Project Tokens and Critical Sandbox Flaws
YApi, a widely used open-source API documentation and mocking platform with 27.7k GitHub stars, has received no updates since its 1.12 release in November 2022. The project accumulated 1,629 open issues, including an unaddressed remote code execution report via mock scripts. Security researcher Perruer created the Yapix fork to address broken dependencies, Node.js 22 incompatibility with deprecated crypto.createCipher, and 244 known vulnerabilities in production dependencies. Analysis revealed that project tokens could be forged by any user because the default passsalt key was a hardcoded five-character string published on GitHub. The original implementation used vm2 and Node vm for script execution, both of which are unsafe, allowing arbitrary server-side code execution. Yapix migrates to isolated-vm with strict memory and time limits, replaces SHA-1 password hashing with scrypt, and blocks MongoDB operator injection in API parameters.
Researchers Bypass RP2350 Secure Debug Lock with Laser Fault Injection and Photon Emission Microscopy
Security researchers have demonstrated a hardware attack that restores Secure Debug access on the RP2350 microcontroller revision A4 despite permanent OTP fuses disabling it. Using photon emission microscopy they first located the exact physical bits of the DEBUGEN register, then applied precisely timed 980 nm laser pulses to flip two critical bits and re-enable the Mem-AP ports. The attack requires decapping the chip from the backside and laboratory equipment costing around $250,000, but succeeds in seconds once calibrated. It bypasses the CRIT1.DEBUG_DISABLE fuse, TrustZone restrictions, and glitch detectors by resetting the device before firmware can re-lock the OTP page. The technique was developed against the updated A4 silicon released after the first Raspberry Pi Hacking Challenge. The work highlights that even heavily hardened microcontrollers remain vulnerable to sophisticated physical attacks when an attacker has direct silicon access.
ServiceNow AI Platform Affected by Five Vulnerabilities Including Critical SQL Injection Flaws
ServiceNow disclosed five vulnerabilities in its AI Platform on September 24, 2026, through a security advisory. Two of the issues received CVSS v4.0 base scores of 9.3 and were rated Critical. CVE-2026-13016 allows unauthenticated remote attackers to perform SQL injection and manipulate database contents under specific conditions. CVE-2026-86860 stems from improper authorization checks that enable data exfiltration and privilege escalation without authentication. The flaws were identified via internal testing, coordinated disclosure, and the company's bug bounty program. ServiceNow urges customers to apply the provided updates immediately to mitigate the risks.