Critical Citrix NetScaler Zero-Days Are Under Active Attack: What Your Business Needs to Do This Week
A pair of critical, unauthenticated zero-day vulnerabilities in Citrix NetScaler are being actively exploited right now and with roughly 23,000 internet-exposed devices worldwide, this is a "patch today, not next sprint" moment that shows exactly why continuous vulnerability management can't be a once-a-quarter checkbox for any growing business.
If your business, or your IT provider, runs Citrix NetScaler to handle remote access, VPN connections, or application delivery, this week's cybersecurity news should move to the top of your to-do list. On September 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency alert confirming that two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited by attackers around the world.
The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, both carry a severity rating of 9.5 out of 10 on the CVSS v4.0 scale about as serious as vulnerability ratings get. CVE-2026-88771 stems from improper input validation and allows an unauthenticated attacker to execute arbitrary commands on a default NetScaler configuration, with no login credentials required. CVE-2026-88772 is a memory overflow flaw that can trigger remote code execution or a denial-of-service condition on systems where DTLS is enabled, which is the default setting on NetScaler VPN servers. Citrix has confirmed that both vulnerabilities are being actively exploited "on unmitigated NetScaler deployments," and researchers tracking the incident say attackers are injecting shellcode directly into device memory to gain a foothold.
CISA's Binding Operational Directive gives federal agencies until September 30, 2026, to patch. There is no such grace period for the private sector, and security researchers estimate roughly 23,000 NetScaler instances remain exposed to the internet globally, with patch status on most of them unknown.
Why This Matters If You're Not a Federal Agency
It's tempting to read a story like this and assume it's only relevant to government IT departments. It isn't. NetScaler is widely used by small and mid-sized businesses precisely because it's an affordable, flexible way to give employees secure remote access, the same reason it's now such an attractive target. A single exposed, unpatched appliance can hand an attacker a direct path into your network, your email, and your client data, all without needing a password.
This is also a case study in why "patch management" belongs on every business's cybersecurity checklist, not just its IT provider's. Frameworks that SMBs are increasingly expected to align with, including the NIST Cybersecurity Framework (CSF) and the CIS Critical Security Controls, both treat vulnerability and patch management as foundational safeguards, not optional extras. An incident like this is exactly what those controls are designed to prevent: a known, actively exploited flaw sitting unpatched on an internet-facing system for days or weeks because no one owned the process of tracking and closing it.
What Citrix & CISA Are Telling Organizations to Do Right Now
Citrix and federal cybersecurity officials are urging every organization running NetScaler ADC or Gateway — across MPX, VPX, SDX-hosted VPX, and CPX deployments — to treat this as an emergency, not routine maintenance:
- 1.Inventory every NetScaler instance, including high-availability pairs and disaster-recovery systems. Shadow IT and forgotten appliances are often the ones that get missed.
- 2.Check for signs of compromise before patching. Because the update may erase forensic evidence, Citrix recommends preserving logs, snapshots, and support bundles first, and looking for unauthorized shell activity, unexpected files, or configuration changes.
- 3.Apply the official Citrix fix referenced in security bulletin CTX697096 as soon as possible. There is no workaround — patching is the only real fix.
- 4.Rotate credentials and secrets after patching, including admin (nsroot) accounts, LDAP/Active Directory bind accounts, SAML/OAuth secrets, and TLS keys, in case they were exposed before the fix was applied.
- 5.Harden the appliance going forward by disabling unused features, enforcing multifactor authentication wherever possible, and turning on comprehensive logging so the next incident is caught faster.
If your business doesn't have the internal expertise to complete that checklist confidently — particularly the "check for compromise before you patch" step — this is precisely the kind of moment a managed IT or security partner earns their keep. Knowing an alert exists is one thing; having someone actively watching for it, triaging it, and acting within hours instead of weeks is another.
Also Worth Knowing This WeekThe Bottom Line
None of these stories are really about one vendor's software bug or one federal task force's memo. They're about the same underlying truth: cybersecurity and compliance are not events; they're ongoing operational disciplines. A critical, actively exploited vulnerability can appear in widely trusted infrastructure with no warning, and the businesses that weather it best are the ones who already have an inventory of what they run, a process for triaging alerts like this one, and a partner who's watching when they can't be.
If you're not certain whether your organization uses NetScaler, whether it's been patched, or whether your broader vulnerability management process would catch the next one of these, now is a good time to find out.
