#NetScaler
By me: Companies around the world are scrambling to patch their Citrix NetScaler systems against ongoing cyberattacks involving two zero-days. Mandiant says the mass-hacks date back at least to early September, with dozens of orgs known to be affected so far — a number that's expected to rise.
Assume compromise: Hackers are mass-exploiting Citrix NetScaler systems in ongoing cyberattacks
Organizations around the world are pulling affected Citrix NetScaler servers out of service, causing outages and public-facing disruption.
this.weekinsecurity.com
October 2, 2026 at 10:22 PM
⚠️ 📢 Sicherheitswarnung: Am 27.09.2026 veröffentlichte der Hersteller #Citrix ein Advisory zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC und NetScaler Gateway. Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen.

👉️ https://www.bsi.bund.de/dok/1209522
Version 1.0: Citrix NetScaler - Systeme werden über ZeroDay-Schwachstellen angegriffen
Am 27. September 2026 veröffentlichte der Hersteller Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei ZeroDay-Schwachstellen, zu denen sich im Lauf...
www.bsi.bund.de
September 28, 2026 at 1:04 PM
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed.

ifin.network/t/multi...

#ThreatIntel #ThreatIntelligence #IFIN
Multiple Citrix Netscaler 0-Days Exploited
Last Updated: 2026-09-29T14:53:55Z (UTC) What’s Happening Citrix has disclosed 8 critical CVEs. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 There’s also an associated blog post. Affected Versions Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23 Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279 Indicato...
ifin.network
September 29, 2026 at 3:21 PM
Citrix NetScaler: new critical vulns, same old story

Citrix patched eight CVEs in NetScaler yesterday, including three critical RCE flaws already under active exploitation. The recurring "patch dump, then active exploitation" for NetScaler is an annual tradition.
September 29, 2026 at 6:38 PM
Citrix NetScaler 0-day active for weeks

Citrix NetScaler vulnerabilities (CVE-2026-88771, -88772) were actively exploited against critical sectors for weeks before disclosure. Users must check for compromise *before* patching.
September 30, 2026 at 11:05 AM
If you want a great example of a security vendor chasing trends while their product burns down due to customers fleeing over vulnerabilities

left: Citrix Netscaler internet facing devices over 5 years
right: Netscaler blog
August 27, 2025 at 9:36 PM
!VAKAVA VAROITUS TRAFICOMILTA!

Citrix NetScaler ADC- ja Gateway-tuotteissa kriittisiä haavoittuvuuksia, useita tietomurtoja Suomessa | Traficom

kyberturvallisuuskeskus.fi/fi/varoituks...
Citrix NetScaler ADC- ja Gateway-tuotteissa kriittisiä haavoittuvuuksia, useita tietomurtoja Suomessa | Traficom
Kyberturvallisuuskeskus on saanut ilmoituksia Citrix NetScaler ADC- ja NetScaler Gateway -tuotteiden kriittisten haavoittuvuuksien aktiivisesta hyväksikäytöstä Suomessa. Haavoittuvuuksien vaikutuspiir...
kyberturvallisuuskeskus.fi
October 2, 2026 at 8:14 AM
Enterprise software maker Citrix has warned customers about an increase in password-spraying attacks against NetScaler appliances: www.citrix.com/blogs/2024/1...

The warning comes days after a similar alert was issued by the BSI, Germany's cybersecurity agency: www.bsi.bund.de/SharedDocs/C...
Password spraying attacks on NetScaler/NetScaler Gateway – December 2024 - Citrix Blogs
A series of recommendations to mitigate recent password spraying attacks on NetScaler/NetScaler Gateway.
www.citrix.com
December 14, 2024 at 11:46 PM
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Read more⬇️
www.ncsc.gov.uk/news/exploit...
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
www.ncsc.gov.uk
September 28, 2026 at 12:49 PM
This kinda happened during the NetScaler zero-day window.... would you consider NetScaler a security product?
September 28, 2026 at 9:10 PM
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
www.bleepingcomputer.com
September 29, 2026 at 6:37 PM
Update zum NetScaler-Zero-Day: Ein kommunaler ISB berichtet mir, dass Citrix nach Eröffnung eines Support-Tickets bereits einen noch ungetesteten Patch bereitgestellt hat.

#ITSicherheit #NetScaler
(Vor-)Warnung zu Citrix NetScaler: Die Hinweise auf eine bislang ungepatchte Zero-Day-Schwachstelle verdichten sich.

Sicherheitsforscher Kevin Beaumont schreibt, die Lücke sei real und werde bereits aktiv ausgenutzt. Einen Patch gibt es derzeit noch nicht.

#ITSicherheit #NetScaler
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 1 image There are rumours swirling for the past week behind the scenes that there are two actively exploited zero days in Citrix Netscaler. The rumours have now broken containment to Reddit...
cyberplace.social
September 27, 2026 at 1:31 PM
Heads up for Citrix customers: CISA is amplifying the vendor's urgent warnings about a series of vulnerabilities in NetScaler security products.

www.cisa.gov/news-events/...

CISA says it has intelligence showing that "threat actors are actively exploiting these vulnerabilities globally."
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | CISA
www.cisa.gov
September 28, 2026 at 2:03 PM
Two recently patched Citrix NetScaler zero-days are seeing widespread mass-exploitation after detailed write-ups and POCs were published on Monday

www.greynoise.io/blog/swarmin...

x.com/LupovisDefen...

mastodon.social/@GossiTheDog...
Swarming Against Citrix 0-Day Exploitation
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
www.greynoise.io
September 29, 2026 at 4:32 PM
Citrix NetScaler and ADC customers the last 12ish hours:
Michael Scott's 'Everybody Stay Calm' Moment
ALT: Michael Scott's 'Everybody Stay Calm' Moment
static.klipy.com
September 26, 2026 at 6:08 PM
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
www.bleepingcomputer.com
September 29, 2026 at 7:43 PM
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt the…
#hackernews #news
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
thehackernews.com
October 1, 2026 at 11:56 PM
die zitten dan waarschijnlijk achter een Citrix Netscaler
September 28, 2026 at 3:45 PM
⚠️ Vulnérabilités Citrix NetScaler ADC et Gateway.

📢 Le @cert-fr.bsky.social publie un bulletin d'alerte concernant plusieurs vulnérabilités affectant NetScaler ADC et Gateway.

➡️ Plus d'informations sur :
www.cert.ssi.gouv.fr/alerte/CERTF...
September 28, 2026 at 9:14 AM
Betreut jemand #Citrix #Netscaler ADC-Installationen? Nach dem Patch vom letzten Wochenende gibt es wohl ein #SAML-Problem. Derzeit stürzen gepatchte, aber angegriffene Netscaler Applicances ab. Citrix untersucht es.

borncity.com/blog/2026/10...
Citrix NetScaler ADC: Neues SAML-Authentifizierungsproblem? (3.10.2026)
Nach dem Patch ist vor der nächsten Schwachstelle. Erst Ende September 2026 gab es ein Notfall-Update zum Schließen von Sicherheitslücken im Citrix NetScaler ADC. Aktuell untersucht das Entwicklungs…
borncity.com
October 3, 2026 at 10:56 AM
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi...

Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
September 27, 2026 at 7:58 PM
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
www.bleepingcomputer.com
September 28, 2026 at 6:24 AM