The Canadian Centre for Cyber Security published a daily advisory digest on 2026-07-15 containing five security advisories covering HPE, Google Chrome, Citrix, Notepad++, and F5 products. The Citrix advisory explicitly references CVE-2026-53565 and CVE-2026-53566 affecting Citrix Secure Access Client and Citrix Endpoint Analysis Client for Windows. The F5 advisory covers a wide range of NGINX and BIG-IP products. All advisories recommend reviewing vendor publications and applying updates or mitigations promptly.
Citrix
6 posts
Cyber Centre Daily Advisory Digest — 2026-07-15 (5 advisories) Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms The financially motivated threat cluster UNC3753 is conducting a fast-paced data theft and extortion campaign against US legal and professional services. The group leverages vishing and IT helpdesk impersonation to trick targets into installing legitimate RMM and screen-sharing tools, enabling rapid data exfiltration from corporate repositories and VDI environments. Notably, the campaign also involves suspected physical intrusions where actors use USB media to steal data directly from endpoints.
Cyber Centre Daily Advisory Digest — 2026-04-28 (4 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting recent security advisories from SmarterTools, Zyxel, Citrix, and Mozilla. Notably, Zyxel addressed command injection vulnerabilities across various networking devices, while the other vendors released standard security updates for their respective software products.
Cyber Centre Daily Advisory Digest — 2026-03-30 (10 advisories) The Canadian Centre for Cyber Security released a daily digest of 10 security advisories highlighting critical vulnerabilities across multiple vendors. Notably, vulnerabilities in Fortinet FortiClientEMS (CVE-2026-21643) and Citrix NetScaler (CVE-2026-3055) are currently being exploited in the wild, requiring immediate patching and potential incident response actions if compromise is suspected.
Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway The NCSC has issued an alert regarding two vulnerabilities in customer-managed Citrix NetScaler ADC and Gateway appliances. CVE-2026-3055 allows for a memory overread in SAML IDP configurations, while CVE-2026-4368 causes user session mixups via a race condition in Gateway or AAA virtual server configurations. Immediate patching is strongly recommended.
Security Advisory 2026-003 Citrix has released security updates addressing two vulnerabilities in NetScaler ADC and Gateway, including a critical out-of-bounds read (CVE-2026-3055) and a high-severity race condition (CVE-2026-4368). These flaws can lead to sensitive information disclosure and user session mix-up, requiring immediate patching and session termination to prevent potential exploitation.