Skip to content
RegionAmericas

HighII Cyber Warfare & Critical Infrastructure28 September 2026, Monday

Citrix NetScaler flaws exploited for weeks as CISA orders urgent patching

Citrix disclosed 8 vulnerabilities in NetScaler ADC and Gateway on 27 September. Two remote code execution flaws rated 9.5 on CVSS had been exploited as zero-days before disclosure. CISA added both to its KEV list and gave federal agencies a 30 September deadline.

Location: WASHINGTON

According to a Rapid7 alert on 28 September, Citrix disclosed 8 vulnerabilities in NetScaler ADC and NetScaler Gateway on 27 September. Two of them, CVE-2026-88771 and CVE-2026-88772, are rated critical at 9.5 on CVSS. Both were exploited as zero-days, meaning no patch existed, before the vendor's disclosure. Rapid7 said 88771 works in the default configuration with low attack complexity, while 88772 requires the DTLS feature to be enabled. According to Security Affairs, DTLS is enabled by default on VPN virtual servers. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalogue on 27 September and gave federal civilian agencies until 30 September to patch.

Help Net Security reported on 28 September that the attacks ran throughout September, weeks before public disclosure. The Dutch National Cyber Security Centre, NCSC-NL, issued the first warnings, and public-sector sources in Europe alerted organisations during the week. According to the report, attackers planted web shells on compromised devices and wiped forensic traces. The operation is assessed as likely state-linked espionage. Sources diverge on the patch release date. Security Affairs and Rapid7 say the Citrix bulletin came out on 27 September, while Help Net Security says the patch was released on 28 September. The patched versions are 14.1-73.37 and 13.1-64.23; the number of affected devices could not be verified.

Talay assessment

Bottom line

Because the zero-day flaws in remote-access gateways were exploited for weeks before a patch appeared, patching alone is not enough; organisations need to hunt for traces on their devices. The attackers' wiping of traces suggests it will remain unclear for an extended period how many organisations were affected. The 30 September deadline will bring a rapid patching wave across the US public sector, while the private sector may patch more slowly.

Likely effects

  • Public-sector networksNegativeWeeks

    Federal agencies must patch and hunt for traces against a tight deadline; if web shells remain on compromised devices, the patch does not cut off access.

  • European organisationsNegativeWeeks

    That the first warning came from the Netherlands shows public and private organisations in Europe are also within the target set.

  • TürkiyeNegativeWeeks

    Turkish organisations using the same product also fall within the scope of the global exploitation wave; the risk persists if patching and trace hunting are delayed.

Possibilities, ranked

  1. 1
    Patch wave and new disclosures55%

    Organisations apply the patch, and several report breaches after hunting for traces.

    Watch: CISA and NCSC-NL updates, organisational breach notifications

  2. 2
    Attribution becomes clearer30%

    Security firms link the attack to a specific state-linked group, and the target list narrows.

    Watch: Threat reports from security firms

  3. 3
    Spread to ransomware actors15%

    Once the flaws become public knowledge, ransomware groups also start exploiting them.

    Watch: NetScaler-related breaches on ransomware leak sites

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • CVSS score▲ 9.5
  • Disclosed flaws▲ 8

Sources

  1. Rapid7 — Zero-day exploitation of Citrix NetScaler ADC and Gateway
  2. Security Affairs — CISA adds Citrix NetScaler flaws to its KEV catalog
  3. Help Net Security — Citrix NetScaler RCE zero-days exploited for weeks