Cookie Consent by Free Privacy Policy Generator

Critical Citrix NetScaler zero-day vulnerabilities under active exploitation

CISA and Citrix confirmed on 27 September that two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products are being actively exploited in the wild. The Register reports that Citrix released emergency patches for eight vulnerabilities in total, including CVE-2026-88771 and CVE-2026-88772, both of which allow remote code execution. One of the flaws affects every deployment running an affected version, including those in default configurations. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue and confirmed receiving reports of active exploitation targeting these systems.

Why this matters for UK organisations

NetScaler products are widely deployed across UK organisations as application delivery controllers and secure remote access gateways, often sitting at the network perimeter with privileged access to internal systems. Active exploitation of these vulnerabilities means attackers can gain initial access to corporate networks, move laterally, and potentially compromise sensitive systems before detection. For organisations using NetScaler in any capacity, this is not a theoretical risk but confirmed hostile activity targeting a commonly deployed enterprise platform. The fact that one vulnerability affects default configurations removes any assumption that custom deployments might be protected. The operational risk is immediate: unpatched systems are exposed to remote code execution attacks that could result in data exfiltration, ransomware deployment, or persistent access for future attacks.

What to review

Organisations running Citrix NetScaler infrastructure should apply the emergency patches immediately and review access logs for any signs of compromise during the period before patching was completed. If patching cannot be completed within hours, consider isolating affected systems or implementing additional network segmentation until updates are deployed. Review who has administrative access to NetScaler systems and ensure that access is appropriately restricted and monitored. Organisations should also confirm that their incident response plans include procedures for responding to perimeter device compromises, as these systems often serve as initial access points for broader network intrusions.

Source: The Register

News and blog posts
SecurityWeek reports that CISA has added CVE-2026-65660, a vulnerability...
Today's brief reflects three recurring themes that UK organisations should...
CISA and Citrix confirmed on 27 September that two critical zero-day...
Microsoft published threat intelligence on 25 September detailing cloud attacks...