Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Vulnerabilities

Citrix NetScaler ADC & Gateway Critical RCE Vulnerabilities Actively Exploited

28 September 2026 LetsDefend Infosec 5 min read

Introduction

The recent disclosure from Citrix marks a rare instance where critical remote code execution (RCE) flaws are confirmed to be under active exploitation. Both NetScaler ADC and NetScaler Gateway—core components for delivering applications and securing remote access—are impacted. The urgency stems from the fact that one of the vulnerabilities compromises every deployment, even those left in their out‑of‑the‑box state.

What Happened

On September 27, Citrix announced that two separate vulnerabilities in its NetScaler product line have been weaponized by threat actors. The company simultaneously released patches for the flaws and for six additional issues discovered during the same audit. The announcement confirms that malicious actors are already leveraging the weaknesses to execute arbitrary code on vulnerable systems.

Technical Details

The two vulnerabilities share a common trait: they permit unauthenticated attackers to inject and run code on the underlying operating system. While the public advisory does not assign CVE identifiers, the description aligns with classic RCE vectors—typically involving malformed network packets or crafted HTTP requests that bypass input validation.

  • Scope of impact – One flaw affects every NetScaler ADC or Gateway instance running an affected version, regardless of configuration. This includes installations that have never been hardened beyond the vendor‑provided defaults.
  • Attack surface – Both ADC and Gateway expose management interfaces that, when improperly protected, become entry points for exploitation. The vulnerabilities appear to be reachable over the network without prior authentication.
  • Payload execution – Successful exploitation grants the attacker command‑level access, enabling data exfiltration, lateral movement, or deployment of additional malware.

The second vulnerability, while also critical, may have a narrower attack surface based on specific configuration settings. However, Citrix has not disclosed further differentiation, emphasizing that both flaws merit immediate remediation.

Who Is Affected

Any organization that runs Citrix NetScaler ADC or NetScaler Gateway on versions vulnerable to the disclosed flaws is at risk. The affected product list includes:

  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway

Because the first vulnerability impacts all deployments, even environments that have not been customized are exposed. Enterprises that rely on NetScaler for load balancing, SSL offloading, or secure remote access should prioritize verification of their version numbers against Citrix’s advisory.

Why It Matters

Remote code execution represents one of the most severe categories of software weakness. An attacker who can run arbitrary commands on a gateway or ADC can potentially control the flow of traffic to internal applications, intercept sensitive data, or establish a foothold for deeper network intrusion. The fact that exploitation is already observed in the wild eliminates any speculation about the threat’s practicality; the risk is immediate and tangible.

Furthermore, the default‑configuration impact expands the attack surface dramatically. Organizations that assumed a “secure by default” posture now face a scenario where the very first line of defense is compromised. The downstream effects include possible compliance violations, service disruption, and damage to brand reputation.

Exploitation/Attack Information

Evidence of active exploitation surfaced through Citrix’s own monitoring and third‑party threat intelligence feeds. Attackers appear to be targeting the management interfaces directly, sending crafted requests that trigger the underlying flaw. While the exact tooling and command‑and‑control infrastructure have not been disclosed, the pattern mirrors typical exploit‑as‑a‑service operations: low‑skill actors can weaponize publicly available exploit code once a patch is released.

Indicators of compromise (IoCs) are not yet public, but defenders should watch for anomalous traffic to NetScaler management ports (typically 443, 8443, or custom admin ports) originating from unfamiliar IP ranges. Unexpected outbound connections from the ADC or Gateway to external servers may also signal a successful breach.

Recommended Actions

Immediate remediation is the only viable defense. Follow these steps without delay:

  1. Identify vulnerable instances – Use Citrix’s version‑check utility or inventory scripts to locate every NetScaler ADC and Gateway deployment.
  2. Apply the released patches – Download the official fixes from Citrix’s support portal and install them according to the vendor’s guidelines. Verify successful installation via version verification commands.
  3. Restrict management access – Enforce network‑level controls (firewall rules, ACLs) that limit exposure of the ADC/Gateway admin interfaces to trusted IP ranges only.
  4. Enable multi‑factor authentication – Where possible, require MFA for any administrative login to reduce the impact of credential‑based attacks.
  5. Monitor for suspicious activity – Deploy IDS/IPS signatures that detect malformed requests targeting NetScaler services. Correlate logs with known malicious IPs and user‑agent strings.
  6. Review default configurations – Harden any settings that remain at their out‑of‑the‑box values, especially those governing remote management and SSL/TLS termination.
  7. Plan for future updates – Establish a regular patch‑management cadence for all Citrix products to avoid repeat exposure.

Organizations that cannot apply patches immediately should consider temporary mitigations such as network isolation of the affected appliances and strict ingress filtering.

Conclusion

The confirmation of active exploitation against two critical RCE flaws in Citrix NetScaler ADC and Gateway underscores the relentless pressure on infrastructure‑level components. The universal impact of one vulnerability eliminates any reliance on configuration hardening; patching is the sole effective remedy. Security teams must act swiftly, verify remediation, and tighten monitoring to contain potential compromise. Failure to do so invites attackers to commandeer a pivotal point in an organization’s traffic flow, with consequences that can cascade across the entire network.

Sources

  • The Hacker News: https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
#Vulnerabilities #Remote Code Execution #Citrix #Patch Management #Threat Intelligence
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Exploitation/Attack Information Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Vulnerabilities
28 Sep 2026 4 min read

CISA Flags Actively Exploited SharePoint Flaw (CVE‑2026‑65660) with Federal Patch Deadline

CISA has added CVE‑2026‑65660 for Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a September 28 patch deadline for federal agencies. Immediate remediation is required.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

Citrix NetScaler Zero‑Day Exploits (CVE‑2026‑88771/88772) Actively Attacked

Citrix disclosed two critical NetScaler remote code execution flaws, CVE‑2026‑88771 and CVE‑2026‑88772, that are currently being exploited. Security updates are available, and administrators are urged to shut down vulnerable appliances immediately.

LetsDefend Infosec Read more
Vulnerabilities
17 Sep 2026 4 min read

Active Exploitation of Cisco ISE Zero-Day Prompts Emergency Patch

Remote, unauthenticated attackers are actively exploiting a zero‑day authentication bypass in Cisco ISE. Cisco responded with an emergency patch. This brief outlines the incident, technical details, impact, and immediate mitigation steps.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.