Citrix NetScaler: two critical zero-days under active exploitation force a review of remote access
Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which are critical and actively exploited as zero-days. CISA recommends checking for indicators of compromise before applying patches.

News summary
On 27 September 2026, CISA amplified Citrix's advisory regarding eight new vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 to CVE-2026-88778). Two of these, CVE-2026-88771 and CVE-2026-88772, are critical, allow independent remote code execution, and are already being exploited on a global scale.
For many organisations, NetScaler Gateway is the primary entry point for remote working and access to published applications. This makes such flaws particularly severe: these devices are exposed to the Internet by design, and a compromise provides attackers with a foothold within the corporate network.
CISA emphasises that updating these appliances can be complex and may require downtime; therefore, it urges teams to first review the indicators of compromise published by Citrix via NetScaler Console. On 2 October, the agency also added a SIGMA detection rule to help identify suspicious activity within logs.
The key recommendation is not to mistake patching for being safe. If the device was exposed during the exploitation period, applying the update closes the door but does not evict anyone who has already gained entry. It is essential to review logs, sessions, accounts, and configuration changes.
Source: CISA — 27 September 2026
Frequently Asked Questions
- Is installing the patch sufficient?
- Not if the device was exposed while the vulnerability was being exploited. The patch prevents new intrusions, but you must check for indicators of compromise and review previous activity.
- What should be done if an immediate update is not possible?
- Reduce the device's exposure, strengthen monitoring, and schedule the update as soon as possible, following the guidance from the manufacturer and cybersecurity authorities.
If your organisation publishes remote access through NetScaler or another gateway, review its status immediately. At Seintec, we audit your perimeter, apply fixes, and monitor subsequent activity. Speak with our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.