#netscaler
Update zum NetScaler-Zero-Day: Ein kommunaler ISB berichtet mir, dass Citrix nach Eröffnung eines Support-Tickets bereits einen noch ungetesteten Patch bereitgestellt hat.

#ITSicherheit #NetScaler
(Vor-)Warnung zu Citrix NetScaler: Die Hinweise auf eine bislang ungepatchte Zero-Day-Schwachstelle verdichten sich.

Sicherheitsforscher Kevin Beaumont schreibt, die Lücke sei real und werde bereits aktiv ausgenutzt. Einen Patch gibt es derzeit noch nicht.

#ITSicherheit #NetScaler
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 1 image There are rumours swirling for the past week behind the scenes that there are two actively exploited zero days in Citrix Netscaler. The rumours have now broken containment to Reddit...
cyberplace.social
September 27, 2026 at 1:31 PM
Citrix NetScaler and ADC customers the last 12ish hours:
Michael Scott's 'Everybody Stay Calm' Moment
ALT: Michael Scott's 'Everybody Stay Calm' Moment
static.klipy.com
September 26, 2026 at 6:08 PM
If you want a great example of a security vendor chasing trends while their product burns down due to customers fleeing over vulnerabilities

left: Citrix Netscaler internet facing devices over 5 years
right: Netscaler blog
August 27, 2025 at 9:36 PM
Update zur heute sehr dynamischen NetScaler-Lage:

Citrix hat inzwischen Fix-Builds veröffentlicht. Für 14.1 steht Build 73.37 bereit, für 13.1 Build 64.24.

Advisory:
support.citrix.com/support-home...

#ITSicherheit #NetScaler
September 27, 2026 at 4:35 PM
CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validat…

https://planetbriefing.com/events/cve-2026-88771-citrix-netscaler-improper-input-validation-vulnerability-784752551976

#Technology #UnitedStates
September 28, 2026 at 1:55 AM
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
www.cyber.gc.ca
September 27, 2026 at 8:39 PM
⚠️ Vulnérabilités Citrix NetScaler ADC et Gateway.

📢 Le @cert-fr.bsky.social publie un bulletin d'alerte concernant plusieurs vulnérabilités affectant NetScaler ADC et Gateway.

➡️ Plus d'informations sur :
www.cert.ssi.gouv.fr/alerte/CERTF...
September 28, 2026 at 9:14 AM
Enterprise software maker Citrix has warned customers about an increase in password-spraying attacks against NetScaler appliances: www.citrix.com/blogs/2024/1...

The warning comes days after a similar alert was issued by the BSI, Germany's cybersecurity agency: www.bsi.bund.de/SharedDocs/C...
Password spraying attacks on NetScaler/NetScaler Gateway – December 2024 - Citrix Blogs
A series of recommendations to mitigate recent password spraying attacks on NetScaler/NetScaler Gateway.
www.citrix.com
December 14, 2024 at 11:46 PM
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi...

Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
September 27, 2026 at 7:58 PM
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story.

ifin.network/t/citri...

#ThreatIntel #ThreatIntelligence #IFIN
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
ifin.network
September 26, 2026 at 11:41 PM
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
www.bleepingcomputer.com
September 28, 2026 at 6:24 AM
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com...

Confirmation 1: mastodon.social/@GossiTheDog...

Confirmation 2: www.linkedin.com/feed/update/...
From the Citrix community on Reddit
Explore this post and more from the Citrix community
www.reddit.com
September 26, 2026 at 10:14 PM
Citrix confirma dos nuevas fallas en NetScaler exploitadas como Cero-Día

Citrix confirmó dos nuevas fallas en NetScaler explotadas como…

https://mentehackers.com/citrix-confirma-dos-nuevas-fallas-en-netscaler-exploitadas-como-cero-dia-b4cab2f4
#Ciberseguridad #Tecnologia #MenteHackers
Citrix confirma dos nuevas fallas en NetScaler exploitadas como
Citrix confirmó dos nuevas fallas en NetScaler explotadas como cero-día. Las vulnerabilidades afectan sistemas de red y pueden permitir acceso no autorizado.
mentehackers.com
September 27, 2026 at 7:07 PM
Citrix Netscaler ADC oder Gateway im Einsatz? 8 kritische Schwachstellen (CVSS Score bis 9.5) am Sonntag geschlossen. Sofort updaten und schauen, ob man kompromittiert ist.

borncity.com/blog/2026/09...
Kritische Schwachstellen in Citrix NetScaler ADC / Citrix NetScaler Gateway (27.9.2026)
Die Gerüchte vom Freitag über größere Schwachstellen in Citrix NetScaler ADC / Citrix NetScaler Gateway, die seit dem 24.9.2026 angegriffen werden, haben sich bestätigt. Citrix hat zum Sonntag, den 27...
borncity.com
September 28, 2026 at 6:51 AM
Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier:
Citrix Patches Two Exploited NetScaler RCE Zero-Days - Cyber Kendra
Citrix patches exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5. Update to 14.1-73.37 or 13.1-64.23 now.
www.cyberkendra.com
September 27, 2026 at 5:33 PM
watchTowr says two unpatched NetScaler RCE zero-days are already being exploited - no patch yet. https://intel.threadlinqs.com/threat/TL-2026-2682 #ThreatIntel #watchTowr #NetScaler #Citrix
September 27, 2026 at 5:06 AM
NetScaler alert: watchTowr says reports of unpatched remote code execution flaws in Citrix NetScaler are verified, and organisations are shutting appliances down. There's no Citrix advisory, CVE or patch yet
www.cyberkendra.com/2026/09/nets...
#NetScaler #Citrix #ZeroDay #CyberSecurity #InfoSec
September 26, 2026 at 6:58 PM
Citrix confirmed two critical NetScaler zero-day flaws were exploited allowing remote code execution; patches are now available and admins are urged to update immediately.

Full synthesis & sources: yasna.io
Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix confirmed two critical NetScaler zero-day flaws were exploited allowing remote code execution; patches are now available and admins are urged to update immediately.
yasna.io
September 28, 2026 at 12:13 AM
Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, ...
community.citrix.com
September 27, 2026 at 8:05 PM
Two unpatched Citrix NetScaler zero-days are under active exploitation, enabling remote code execution. Citrix has not released a fix yet, and some admins are isolating appliances. #Citrix #NetScaler #ZeroDay
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two newly uncovered, unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild, according to watchTowr. Administrators are being urged to isolate or shut down appliances while awaiting Citrix guidance, as no fix, workaround, or indicators of compromise have yet been published. #Citrix #NetScalerADC...
www.hendryadrian.com
September 27, 2026 at 1:45 PM
(Vor-)Warnung zu Citrix NetScaler: Die Hinweise auf eine bislang ungepatchte Zero-Day-Schwachstelle verdichten sich.

Sicherheitsforscher Kevin Beaumont schreibt, die Lücke sei real und werde bereits aktiv ausgenutzt. Einen Patch gibt es derzeit noch nicht.

#ITSicherheit #NetScaler
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 1 image There are rumours swirling for the past week behind the scenes that there are two actively exploited zero days in Citrix Netscaler. The rumours have now broken containment to Reddit...
cyberplace.social
September 27, 2026 at 7:58 AM
Shoutout to the folks on that Citrix subreddit thread, the security researchers validating the bugs, and the random IT teams who proactively reached out to affected NetScaler customers over the weekend, all of whom did a far better job at mitigating the damage before Citrix joined the party.
September 27, 2026 at 8:01 PM
🌊 ABYSSAL · critical with a public exploit
CVE-2026-88772: Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, b…
CVSS 9.5 · exploited
https://beta.vulnsea.com/cve/CVE-2026-88772

#CVE #infosec #cybersecurity #threatintel
CVE-2026-88772 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-…
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-…
beta.vulnsea.com
September 27, 2026 at 9:23 PM