Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: + –
5 minutes reading time (960 words)

Critical Citrix NetScaler Zero-Days Are Under Active Attack: What Your Business Needs to Do This Week

A pair of critical, unauthenticated zero-day vulnerabilities in Citrix NetScaler are being actively exploited right now and with roughly 23,000 internet-exposed devices worldwide, this is a "patch today, not next sprint" moment that shows exactly why continuous vulnerability management can't be a once-a-quarter checkbox for any growing business.

If your business, or your IT provider, runs Citrix NetScaler to handle remote access, VPN connections, or application delivery, this week's cybersecurity news should move to the top of your to-do list. On September 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency alert confirming that two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited by attackers around the world.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, both carry a severity rating of 9.5 out of 10 on the CVSS v4.0 scale about as serious as vulnerability ratings get. CVE-2026-88771 stems from improper input validation and allows an unauthenticated attacker to execute arbitrary commands on a default NetScaler configuration, with no login credentials required. CVE-2026-88772 is a memory overflow flaw that can trigger remote code execution or a denial-of-service condition on systems where DTLS is enabled, which is the default setting on NetScaler VPN servers. Citrix has confirmed that both vulnerabilities are being actively exploited "on unmitigated NetScaler deployments," and researchers tracking the incident say attackers are injecting shellcode directly into device memory to gain a foothold.

CISA's Binding Operational Directive gives federal agencies until September 30, 2026, to patch. There is no such grace period for the private sector, and security researchers estimate roughly 23,000 NetScaler instances remain exposed to the internet globally, with patch status on most of them unknown.

Why This Matters If You're Not a Federal Agency

It's tempting to read a story like this and assume it's only relevant to government IT departments. It isn't. NetScaler is widely used by small and mid-sized businesses precisely because it's an affordable, flexible way to give employees secure remote access, the same reason it's now such an attractive target. A single exposed, unpatched appliance can hand an attacker a direct path into your network, your email, and your client data, all without needing a password.

This is also a case study in why "patch management" belongs on every business's cybersecurity checklist, not just its IT provider's. Frameworks that SMBs are increasingly expected to align with, including the NIST Cybersecurity Framework (CSF) and the CIS Critical Security Controls, both treat vulnerability and patch management as foundational safeguards, not optional extras. An incident like this is exactly what those controls are designed to prevent: a known, actively exploited flaw sitting unpatched on an internet-facing system for days or weeks because no one owned the process of tracking and closing it.

What Citrix & CISA Are Telling Organizations to Do Right Now 

Citrix and federal cybersecurity officials are urging every organization running NetScaler ADC or Gateway — across MPX, VPX, SDX-hosted VPX, and CPX deployments — to treat this as an emergency, not routine maintenance:

  • 1.Inventory every NetScaler instance, including high-availability pairs and disaster-recovery systems. Shadow IT and forgotten appliances are often the ones that get missed.
  • 2.Check for signs of compromise before patching. Because the update may erase forensic evidence, Citrix recommends preserving logs, snapshots, and support bundles first, and looking for unauthorized shell activity, unexpected files, or configuration changes.
  • 3.Apply the official Citrix fix referenced in security bulletin CTX697096 as soon as possible. There is no workaround — patching is the only real fix.
  • 4.Rotate credentials and secrets after patching, including admin (nsroot) accounts, LDAP/Active Directory bind accounts, SAML/OAuth secrets, and TLS keys, in case they were exposed before the fix was applied.
  • 5.Harden the appliance going forward by disabling unused features, enforcing multifactor authentication wherever possible, and turning on comprehensive logging so the next incident is caught faster.

If your business doesn't have the internal expertise to complete that checklist confidently — particularly the "check for compromise before you patch" step — this is precisely the kind of moment a managed IT or security partner earns their keep. Knowing an alert exists is one thing; having someone actively watching for it, triaging it, and acting within hours instead of weeks is another.

Also Worth Knowing This Week 

This wasn't the only development worth a small or mid-sized business's attention. The Department of Defense's CMMC Reform Task Force confirmed on September 22 that contractors and subcontractors in the defense industrial base, along with the MSPs and IT providers that support them, must continue self-assessing against the full CMMC framework and all 171 NIST SP 800-171 controls while the broader rule review continues, with growing emphasis on documented evidence rather than good intentions. Separately, international law enforcement dismantled "EvilTokens," a phishing-as-a-service platform that had industrialized attacks against Microsoft 365, Gmail, and Okta accounts by exploiting device-code login flows on smart TVs, printers, and conference-room hardware a reminder that the "smart" devices in your office can be a backdoor into your core business accounts if they're not part of your security review.

The Bottom Line

None of these stories are really about one vendor's software bug or one federal task force's memo. They're about the same underlying truth: cybersecurity and compliance are not events; they're ongoing operational disciplines. A critical, actively exploited vulnerability can appear in widely trusted infrastructure with no warning, and the businesses that weather it best are the ones who already have an inventory of what they run, a process for triaging alerts like this one, and a partner who's watching when they can't be.

If you're not certain whether your organization uses NetScaler, whether it's been patched, or whether your broader vulnerability management process would catch the next one of these, now is a good time to find out.

Cybersecurity Threat Advisory: WordPress "Click2Sh...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024