Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Cybersecurity

Citrix NetScaler exploited before a patch existed

28 September 2026·Trung Nguyễn Dúce
Citrix NetScaler exploited before a patch existed

Citrix has confirmed that two vulnerabilities in NetScaler ADC and NetScaler Gateway were being exploited at customers worldwide before an update was available. The Dutch National Cyber Security Centre raised its advisory to the highest level and urges organisations to install the updates as soon as possible. If your remote access runs through Citrix, this cannot wait for the next patch round.

What is going on

Two flaws carry the highest severity scores. CVE-2026-88771 lets an attacker run commands on the appliance remotely, without credentials, and affects every deployment regardless of how the NetScaler is configured. The second flaw, CVE-2026-88772, causes memory problems that can lead to code execution or an outage, and works through DTLS — a protocol enabled by default on VPN virtual servers.

Citrix has released updates that close these two flaws along with six others. Affected are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, including the FIPS variants and Secure Private Access in hybrid deployments. The NCSC advisory lists eight CVEs in total.

Why updating is not the whole job

With an ordinary vulnerability, applying the update ends the story. Not here. Because the exploitation started before the updates existed, the update only closes the door — it tells you nothing about whether someone already walked through it. The researchers who spotted the attacks first make the point plainly: the appliance's patch status says nothing about the period before it.

A NetScaler also sits in an awkward place: at the edge of your network, reachable from the internet, holding sessions, certificates and account details. Anyone who gets in there no longer needs a phishing email. That makes the evidence more important than the speed of the update.

What to do now

  1. Preserve log files and memory data first, going back at least a month. An update overwrites exactly the material you need later to establish what happened.
  2. Then update to the versions in the Citrix bulletin. Expect a short outage, and schedule it today rather than postponing it.
  3. Replace passwords and keys for service accounts and for users who work through the NetScaler, and revoke certificates where you can. Anything an attacker took earlier otherwise stays valid.
  4. Keep a closer eye on the appliance and the systems behind it for a few weeks, watching for sessions and sign-in attempts that do not match your own people.
  5. If you cannot update straight away, reduce the appliance's exposure to the internet until you can.

If you do not know whether a NetScaler sits in your environment, ask that first. The appliance lives under the bonnet of “logging in remotely”, which is why it goes unnoticed.

The lesson if you do not use Citrix

This is the third year running in which edge equipment — firewalls, VPN concentrators, access portals — forms the starting point of attacks. Two things then decide how well you come out of it. The first is a current list of everything you have facing the internet, with version numbers, so that when an advisory lands you know within the hour whether it affects you. The second is log retention that reaches back further than a few days, because without logs the question “were we hit?” cannot be answered. Both are easier to arrange on a quiet day than on the Sunday a vendor publishes an advisory.

At Qteco we track advisories like this one for the environments we manage, check whether customers are affected, and update with evidence preserved beforehand. If you would like to know where your own edge equipment and log retention stand, book a conversation with one of our engineers.

Sources

  1. Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu — NCSC (2026-09-27)
  2. Citrix confirms two NetScaler RCE zero-days exploited in attacks — BleepingComputer (2026-09-27)
  3. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation — The Hacker News (2026-09-26)

Read also

Stolen session tokens walk straight past your MFA

Why two-step verification does not stop this phishing

Record Windows update round with two exploited flaws

Ready to run worry-free?

Book a no-obligation introduction. We map your IT and security and show where the difference lies.

Book a call →