Skip to main content

Citrix NetScaler: two critical zero-days under active exploitation force a review of remote access

Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which are critical and actively exploited as zero-days. CISA recommends checking for indicators of compromise before applying patches.

CybersecuritySeintec team3 min read
Citrix NetScaler: two critical zero-days under active exploitation force a review of remote access

News summary

On 27 September 2026, CISA amplified Citrix's advisory regarding eight new vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771 to CVE-2026-88778). Two of these, CVE-2026-88771 and CVE-2026-88772, are critical, allow independent remote code execution, and are already being exploited on a global scale.

For many organisations, NetScaler Gateway is the primary entry point for remote working and access to published applications. This makes such flaws particularly severe: these devices are exposed to the Internet by design, and a compromise provides attackers with a foothold within the corporate network.

CISA emphasises that updating these appliances can be complex and may require downtime; therefore, it urges teams to first review the indicators of compromise published by Citrix via NetScaler Console. On 2 October, the agency also added a SIGMA detection rule to help identify suspicious activity within logs.

The key recommendation is not to mistake patching for being safe. If the device was exposed during the exploitation period, applying the update closes the door but does not evict anyone who has already gained entry. It is essential to review logs, sessions, accounts, and configuration changes.

Source: CISA — 27 September 2026

Frequently Asked Questions

Is installing the patch sufficient?
Not if the device was exposed while the vulnerability was being exploited. The patch prevents new intrusions, but you must check for indicators of compromise and review previous activity.
What should be done if an immediate update is not possible?
Reduce the device's exposure, strengthen monitoring, and schedule the update as soon as possible, following the guidance from the manufacturer and cybersecurity authorities.

If your organisation publishes remote access through NetScaler or another gateway, review its status immediately. At Seintec, we audit your perimeter, apply fixes, and monitor subsequent activity. Speak with our cybersecurity team.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.