TrustDigital Weekly Brief
Citrix and Microsoft Vulnerabilities You Need to Know
September 28, 2026
This week, we’re focusing on critical security vulnerabilities impacting Citrix products and some important Microsoft updates that could affect your business operations.
CISA has raised alarms over multiple vulnerabilities in Citrix NetScaler ADC and Gateway. Two specific vulnerabilities (CVE-2026-88772 and CVE-2026-88771) are actively exploited, meaning attackers are already taking advantage of them in real-world scenarios. CVE-2026-88772 deals with a memory buffer issue that could allow unauthorized access, while CVE-2026-88771 involves improper input validation that could enable an attacker to execute unauthorized code. The situation highlights the importance of keeping your systems updated and secure.
In response to these vulnerabilities, CISA has added them to its Known Exploited Vulnerabilities Catalog. If your organization utilizes Citrix products, we strongly recommend checking on your systems and applying any available patches. It’s crucial to stay ahead of potential threats by addressing these vulnerabilities promptly.
Shifting to Microsoft, there’s a notable vulnerability in SharePoint (CVE-2026-65660) that involves code injection, which could allow an attacker to execute malicious code over your network if they gain access. Microsoft has issued advisories about this risk, and businesses should consider implementing additional security measures to mitigate the risk.
Also, WordPress users should be aware of CVE-2026-87902, which exposes a remote file inclusion vulnerability. This could potentially allow attackers to manipulate page templates, leading to further exploitation. Keeping plugins and themes updated is essential in preventing such attacks.
Now, regarding upcoming end-of-support deadlines—mark your calendars. Support for Windows 10 1607, Windows 11 24H2, and Microsoft Office 2021 will end on October 13, 2026. For Windows 11 23H2, support ends on November 10, 2026, and Windows 10 21H2 will follow with an end date of January 12, 2027. Ignoring these deadlines could leave your systems vulnerable and limit your access to essential updates and support.
If your organization is still running these versions, we can help you with a smooth transition to supported versions. This process involves evaluating your current hardware and licensing needs, migrating data, and ensuring minimal disruption to your operations. We’ll provide the specifications and quotes to get you set up with the right devices and licenses.
In Microsoft news, an important note: Office LTSC 2021 support will also end on October 13, 2026. Businesses relying on this version need to start planning for an upgrade, so you don’t get caught unprepared.
Finally, we encourage you to think about the Microsoft 365 Backup feature. This tool can enhance your data security and protect your organization’s information better. Enabling backup is a straightforward step that can provide peace of mind.
If you have products from Citrix or Microsoft in your environment, or if you're facing any end-of-support deadlines, we’d like to help. Just reply to this note, or reach out to us at /contact. We're here to assist you in navigating these challenges.