CVE-2026-88771 through CVE-2026-88778 Citrix NetScaler ADC and Gateway Vulnerability Bulletin
Broadridge Logo

Trust Center

Start your security review
ControlK

Welcome to Broadridge's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

The goal of the Broadridge Information Security Group (BISG) is to provide guidance to all Broadridge associates and contingent workers on Information Security standards, polices, and procedures so that they can incorporate security into their job functions

The mission of the BISG is to provide the guidance and practical solutions to support the business to ensure the confidentiality, integrity, and availability of Broadridge’s information assets through the implementation and management of the Information Security Management Program. This includes guidance for the collection, use, maintenance, security, and disclosure practices of personal information by Broadridge and its subsidiaries as outlined in the BR Global Privacy Policy. This involves the creation, administration, and communication of policies and
standards to ensure the correct protection mechanisms are in place to support the mission.

The purpose of the Information Security Management Program is to ensure that management is appropriately advised and supported so that Broadridge can effectively implement security controls that enable Broadridge to meet the requirements of Internal Audit, external auditors, applicable regulations, clients, and other parties that trust Broadridge to safeguard their information.
The charter of the BISG is to:
• Identify/assess operational and application risks/vulnerabilities and propose recommendations for mitigation through the utilization of appropriate information security controls. (Risk Assessment)
• Protect against any anticipated threats and hazards of information resources (Security Incidents).
• Establish controls to prevent loss or compromise of information resources. (Data Loss Prevention)
• Promote information security awareness within the organization. (Training and Awareness)
• Establish core competencies of Information Security within the business. (Standardization)
• Provide guidance on user and system access to ensure appropriateness for
business functions (Entitlements Management)
• Establish control frameworks (ex. ISO, HIPAA, PCI, NIST, SSAE-18) gather
evidence, and report to management the state of information security within the business. (Risk & Compliance)
• Govern the processes to ensure the proper disposal of company and client
information

Trust Center Updates

CVE-2026-88771 through CVE-2026-88778 Citrix NetScaler ADC and Gateway Vulnerability Bulletin

Vulnerabilities

September 27, 2026

BROADRIDGE RESPONSE STATEMENT

Subject: CVE-2026-88771 through CVE-2026-88778 Citrix NetScaler ADC and Gateway Vulnerability Bulletin

On September 27, 2026, Citrix disclosed multiple vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The advisory includes two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, for which Citrix has reported observed exploitation on unmitigated systems. [support.citrix.com], [support.citrix.com]

In response to this advisory, Broadridge immediately initiated its established threat response and vulnerability management processes to assess potentially affected systems and evaluate any potential exposure to client-facing services.

Broadridge has completed the deployment of the Citrix-recommended security updates across applicable NetScaler environments. The updates were implemented in accordance with Broadridge's established vulnerability management and change management processes and address the vulnerabilities identified within the Citrix security bulletin. [support.citrix.com]

Broadridge maintains NetScaler technologies that support certain client-facing services, including services that utilize single sign-on (SSO) authentication. The disclosed vulnerabilities affect the NetScaler technology itself and do not represent a vulnerability within a client's identity provider or authentication platform.

Following the deployment of the security updates, Broadridge conducted validation activities to confirm successful implementation and service stability. At this time, Broadridge has not identified any disruption to client services related to these vulnerabilities.

Broadridge continues to actively monitor vendor guidance, threat intelligence, and the security posture of its environment. Appropriate security controls, monitoring capabilities, vulnerability management practices, and incident response processes remain in place to protect client data and services.

Based on the assessment performed and remediation activities completed, Broadridge believes the risk associated with these vulnerabilities has been appropriately addressed within its managed environment.

Threat Response-FortiBleed Campaign July 6, 2026

Vulnerabilities

BROADRIDGE RESPONSE STATEMENT

Broadridge was notified about the FortiBleed campaign, a large-scale credential-harvesting operation targeting internet-facing Fortinet FortiGate firewalls and SSL VPN appliances. In June 2026, security researchers discovered an exposed threat actor dataset containing valid usernames, email addresses, and plaintext passwords for approximately 73,932 Fortinet devices across 194 countries, representing nearly half of all publicly exposed Fortinet firewalls. The campaign harvested SSL VPN authentication hashes from exposed management interfaces and cracked them offline, primarily targeting devices that retained older, weaker password hash formats.

Unlike a traditional software vulnerability, FortiBleed is not associated with a new CVE or zero-day vulnerability. Instead, it exploits exposed management interfaces, weak authentication practices, compromised credentials, and legacy password hashing mechanisms. On June 18, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) advised organizations to terminate active sessions, reset administrative and VPN passwords, enforce phishing-resistant multi-factor authentication (MFA), inspect logs for unauthorized activity, restrict management interfaces from the public internet, and ensure password hashes are regenerated using Fortinet's stronger PBKDF2 hashing algorithm following software updates.

Broadridge has reviewed the details of the FortiBleed campaign and confirmed that the conditions required for compromise do not exist within the Broadridge environment hence Broadridge is not affected. Broadridge continues to proactively monitor emerging cybersecurity threats and maintains a comprehensive vulnerability management program to help ensure the ongoing protection of our clients, customers, stakeholders, and associates.

Thank you,
Broadridge

Emerging AI-driven cybersecurity risks

General

Broadridge actively monitors emerging AI-driven cybersecurity risks and evaluates their potential impact through our existing enterprise cybersecurity, software security, and risk management programs. With respect to developments such as Anthropic’s Mythos model and Project Glasswing, we are assessing the broader implications of AI-enabled vulnerability discovery and exploitation as part of our ongoing threat monitoring and control evaluation processes.

  1. Assessment and response to emerging AI-driven security risks
    Broadridge is addressing emerging AI-related risks through established governance and security processes, including threat intelligence review, vulnerability management, secure development practices, and third-party risk oversight. We see how AI increases the speed or scale of vulnerability discovery, exploitation attempts, phishing, or other malicious activity, and we have been enhancing our controls to address those risks effectively.

  2. Current and planned controls
    Broadridge maintains layered security controls designed to protect our environment, including secure development practices, vulnerability scanning, patch management, penetration testing, monitoring and detection capabilities, access controls, incident response procedures, and third-party risk management. We are also adopting control enhancements, as appropriate, in areas such as AI governance, monitoring for anomalous activity, secure use of AI-enabled tools, and software supply chain risk management.

  3. Timeframe for enhanced measures
    Our approach is ongoing and risk-based. Many relevant controls are already in place today, including AI based security monitoring, automated controls for remediation and any additional enhancements are being evaluated and implemented through our normal cybersecurity and change management processes based on risk priority.

  4. Vulnerability identification, management, and disclosure
    Broadridge maintains processes to identify, assess, prioritize, remediate, and track vulnerabilities using a combination of scanning, testing, threat intelligence, and internal review. Where a vulnerability or security issue materially affects client data, services, or the Broadridge environment supporting our clients, notification would be made in accordance with applicable contractual obligations and established incident response procedures.

Thank you, Broadridge.

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368

Vulnerabilities

Broadridge Threat Response March 2, 2026.

BROADRIDGE RESPONSE STATEMENT

In March of 2026, Broadridge was notified about two vulnerabilities, CVE-2026-3055 and CVE-2026-4368, affecting NetScaler ADC and NetScaler Gateway.

In response to these vulnerabilities, Broadridge has investigated, and we can confirm we are not impacted by either of the vulnerabilities referenced; however, we are continuously monitoring our environment to ensure our clients, customers, stakeholders, and associates remain unaffected.

Thank you,

Broadridge

MongoBleed (CVE-2025-14847

Vulnerabilities

Threat Response January 15, 2026

BROADRIDGE RESPONSE STATEMENT
On December 29th, 2025, Broadridge was notified about a recent announcement by the Cybersecurity and Infrastructure Security Agency (CISA) regarding MongoDB servers (CVE-2025-14847) which have been actively exploited in the wild. CVE-2025-14847, also known as “MongoBleed”, stems from improper handling of length fields in zlib-compressed network protocol messages, allowing unauthenticated remote attackers to coerce MongoDB into returning uninitialized heap memory to the client.

Affected versions of the MongoBleed (CVE-2025-14847) include:

• MongoDB Server v7.0 prior to 7.0.28 versions
• MongoDB Server v8.0 versions prior to 8.0.17
• MongoDB Server v8.2 versions prior to 8.2.3
• MongoDB Server v6.0 versions prior to 6.0.27
• MongoDB Server v5.0 versions prior to 5.0.32
• MongoDB Server v4.4 versions prior to 4.4.30
• MongoDB Server v4.2 versions greater than or equal to 4.2.0
• MongoDB Server v4.0 versions greater than or equal to 4.0.0
• MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Affected versions should be upgraded to versions equal or greater to the below versions:
• Version 7.0.28
• Version 8.0.17
• Version 8.2.3
• Version 6.0.27
• Version to 5.0.32
• Version 4.4.30

Broadridge has investigated MongoBleed vulnerability (CVE-2025-14847) across the enterprise and has detected a few vulnerable versions of MongoDB. Broadridge has patched most of the instances to the non-vulnerable versions and is in the final stage of upgrading the last few instances. All identified remaining versions will be patched by January 19th, 2025. Broadridge continues to continuously monitor its environments to ensure our clients, customers, stakeholders, and associates remain unaffected by today’s cyber threats.

Thank you, Broadridge

If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo