Disponible uniquement en anglais.

Retour aux ressources Security Advisory

Actively Exploited Citrix NetScaler Vulnerabilities: Actions for Executive Teams

Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the systems many firms use for remote access. Two were exploited before the fix existed: Citrix found them while investigating incidents at customers, and the Dutch National Cyber Security Centre has reported attacks at multiple organisations worldwide.

Authorities are treating this as urgent. CERT-EU is urging organisations to check for signs of compromise as well as patching, and US federal agencies were given three days to secure their appliances. This article explains the business risk, the actions leadership should approve this week, and what regulators in the UK, EU, and Switzerland will expect.

Key Facts

ItemDetail
Vendor bulletinCTX697096, published 27 September 2026 by Cloud Software Group, which owns Citrix
Affected productsCustomer-managed NetScaler ADC and NetScaler Gateway appliances running releases older than those listed in the technical section below
VulnerabilitiesEight fixed. Two were exploited before the fix was released
SeverityRated Critical by the vendor. Both exploited flaws score 9.5 out of 10
Login needed to exploitNone for the most serious flaw, which works against the default configuration
Not affectedCitrix-managed cloud services and Citrix-managed Adaptive Authentication, which the vendor updates itself
Decision needed todayApprove an emergency change to update every appliance, followed by a compromise assessment

Why This Matters to the Business

NetScaler Gateway is the system many firms use for remote access. Staff and contractors log in through it to reach email and client systems, and NetScaler ADC (application delivery controller) routes traffic to important applications. Both are reachable from the internet by design.

Because the most serious flaw needs no login, any internet-facing appliance can be attacked directly. An attacker who takes control of the appliance can capture staff credentials as people log in, take over sessions that are already open, and use the appliance as a route into internal systems.

For the business, that can lead to exposure of client data and loss of remote access while systems are rebuilt. It can also trigger reporting obligations to regulators and clients.

A compromised appliance is harder to detect than a compromised laptop or server. NetScaler appliances cannot run endpoint detection and response (EDR) software, so activity that starts on the appliance can look like normal traffic.

Installing the update stops further attacks through these flaws. It does not remove an attacker who got in before the update, which is why the actions below go beyond patching.

Actions for Leadership

WhenActionOwnerPurpose
TodayIdentify every NetScaler appliance, the software release it runs, and whether it can be reached from the internet. Include appliances run by suppliers on your behalfHead of ITConfirms your exposure
Within 24 hoursUpgrade every customer-managed appliance to a fixed release as an emergency changeHead of IT, with executive approvalCloses the two exploited flaws and the other six
Immediately after upgradingEnd all active user sessions. Change administrator passwords and the passwords of the service accounts NetScaler uses to check logins against your directoryHead of ITRemoves access an attacker may already hold
Within five working daysCommission a compromise assessment covering at least the last 60 days of appliance logs and network activityHead of security or an external incident response firmEstablishes whether anyone got in before the fix
Within five working daysConfirm that the appliance management console cannot be reached from the internetHead of ITCloses a common route to full control of the appliance
Within five working daysDecide whether any regulatory reporting duty applies, and record the decision and the reasoningCompliance leadGives regulators the evidence they will ask for

Appliances on unsupported releases. A release that no longer receives updates cannot be patched. These appliances must first move to a supported release, which takes longer, so identify them today.

Steps beyond the vendor bulletin. The bulletin does not require you to end sessions or change credentials. DarkGuard recommends both because attackers who exploited earlier NetScaler flaws used stolen sessions and credentials to keep their access after systems were patched.

If a supplier runs your remote access. Responsibility for the risk stays with your firm. The EU Digital Operational Resilience Act (DORA) states this explicitly, and the UK Financial Conduct Authority (FCA) applies the same principle to outsourced services. Ask your provider to confirm in writing which release each appliance now runs, when it was updated, and what their compromise check found.

Questions to Put to Your IT Lead This Week

  1. How many NetScaler appliances do we have, including any run by a supplier, and are any on a release that no longer receives updates?
  2. When will every appliance be on a fixed release, and who approved the change?
  3. Have active sessions been ended and the appliance credentials changed?
  4. Who is checking whether we were compromised before the update, and when will we have their findings?
  5. Does anything found so far trigger a reporting duty, and who is responsible for that decision?

Regulatory Expectations

Regulators will want to see that you acted promptly once the fix was published, and that you can evidence each step.

FrameworkApplies toRelevance to this issue
DORAEU financial entities, since 17 January 2025Technology risk management must include timely patching. A major incident requires an initial notification within four hours of classification, and no later than 24 hours after you become aware of it
EU Network and Information Security Directive (NIS2)Essential and important entities, as defined in national lawVulnerability handling is a required security measure. A significant incident requires an early warning within 24 hours and an incident notification within 72 hours
FCAFCA-authorised firmsImportant business services must stay within their impact tolerances. Under Principle 11, you must tell the FCA about anything it would reasonably expect to know, including a material cyber incident
Swiss Financial Market Supervisory Authority (FINMA)FINMA-supervised institutionsFINMA Guidance 05/2020 requires cyber attacks affecting critical assets to be reported within 24 hours, followed by a full report within 72 hours
UK and EU General Data Protection Regulation (GDPR)Any firm processing personal dataA personal data breach that poses a risk to individuals must be reported to the data protection authority within 72 hours

Keep a dated record of when you learned of the bulletin, when the change was approved, when each appliance was updated, and what the compromise assessment found. Supervisors, auditors, and cyber insurers will ask for it.

How DarkGuard Can Help

An internal IT team or provider can usually apply the update. Establishing whether an attacker got in first, and producing a record that will stand up to board and regulatory scrutiny, often needs specialist support. DarkGuard provides:

  • Compromise assessment. A review of your appliances, logs, and network activity, with a clear conclusion on whether they were accessed and what to do next.
  • Remediation support. Planning and sequencing upgrades across high-availability pairs and clusters, working with your team or provider to keep remote access available where your configuration allows.
  • Board and regulatory documentation. A board-ready summary and an evidence file to support your reporting decisions under DORA, NIS2, the FCA, or FINMA.
  • Incident response. If we find evidence of compromise, our senior team leads containment and recovery. They have delivered incident response and board-level exercises for organisations valued at over $220 billion, across banking, insurance, energy, and critical infrastructure

Our engagement ends when every appliance is on a fixed release and the evidence is on file.

Contact our Advisory and Response Desk

If you suspect a compromise, or would like an assessment or advice, contact us:

Technical Detail for IT and Security Teams

Source: Citrix security bulletin CTX697096, published 27 September 2026. The bulletin covers eight Common Vulnerabilities and Exposures (CVE) entries, CVE-2026-88771 to CVE-2026-88778.

Exploited Vulnerabilities

  • CVE-2026-88771: remote code execution caused by improper input validation. No authentication required. Affects all deployments in the default configuration. Common Vulnerability Scoring System (CVSS) v4.0 score 9.5.
  • CVE-2026-88772: memory overflow leading to remote code execution or denial of service. Requires Datagram Transport Layer Security (DTLS), which is enabled by default on virtual private network (VPN) virtual servers. CVSS v4.0 score 9.5

Fixed Releases

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later

Other Vulnerabilities Fixed in the Same Releases

  • CVE-2026-88773: HTTP request smuggling (9.3)
  • CVE-2026-88774: policy bypass through HTTP URL expressions (7.0)
  • CVE-2026-88775 to CVE-2026-88777: memory overflows causing denial of service (8.8 each)
  • CVE-2026-88778: TCP initial sequence number (ISN) prediction (8.8). The upgrade alone does not fix this one. Enable enhanced ISN generation as described in NetScaler’s TCP configuration documentation

DarkGuard Recommendations Beyond the Bulletin

  • If you see signs of compromise, capture a forensic image of the appliance before upgrading, because the upgrade can overwrite evidence. Complete this within hours so it does not delay the upgrade.
  • After upgrading, terminate active sessions. The commands NetScaler published for earlier incidents include kill aaa session -all and kill icaconnection -all.
  • Rotate the Lightweight Directory Access Protocol (LDAP) bind account, local administrator accounts including nsroot, and any credentials stored in the configuration.
  • Look for unfamiliar files in web-served directories, new or changed administrator accounts, unexpected scheduled tasks, and outbound connections from the appliance.
  • Local logs on the appliance rotate quickly, so retrieve historical logs from your security information and event management (SIEM) platform or syslog server