Monday, 28 September 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Citrix patches eight NetScaler flaws as two zero-days are exploited

CISA has given US federal agencies until 30 September to act and the National Cyber Security Centre is telling UK defenders to isolate affected appliances, while some IT suppliers told customers to pull the plug

The facts
  • Citrix released fixes for eight NetScaler ADC and Gateway CVEs, CVE-2026-88771 to CVE-2026-88778, on 27 September.
  • The two exploited flaws each score 9.5 on CVSS v4; the other six range from 7.0 to 9.3.
  • CISA added both exploited flaws to its KEV catalog on 27 September with a 30 September due date for federal agencies.
  • Palo Alto Networks’ Cortex Xpanse counted more than 50,277 exposed instances potentially vulnerable to the two CVEs as of 27 September, its Unit 42 threat brief says.
What it means for partners

For MSPs and managed security service providers (MSSPs) with NetScaler in a customer estate this is a forensic job before it is a patch job: CISA and the NCSC both say check for compromise first, and that is incident-response work most managed-service contracts price separately or not at all. Partners that phoned customers before the bulletin have banked trust a patch cycle never earns; those who learned of it from the news will be asked why. Expect NetScaler Console licenses and hardware refreshes to sell off the back of this, and public-sector buyers to ask at renewal who is accountable for the edge appliance between patches.

“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.”Cybersecurity and Infrastructure Security Agency, alert, US Cybersecurity and Infrastructure Security Agency

Citrix confirmed on 27 September that two critical flaws in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, are being exploited as zero-days, and released fixes for them and six further vulnerabilities in one bulletin. Both score 9.5 on the Common Vulnerability Scoring System (CVSS) v4. The first lets an unauthenticated attacker run commands against a default configuration; the second is a memory overflow that needs Datagram Transport Layer Security (DTLS) switched on, which it is by default on VPN virtual servers.

The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave federal agencies until 30 September to apply the vendor’s mitigations and carry out forensic triage. Its alert says to look for signs of compromise before patching, because an update can wipe the forensic trail.

Isolate first, patch second

The National Cyber Security Centre (NCSC) published its own alert on 28 September and is still assessing the impact on UK organizations. Its priority list puts patching fifth: identify affected systems, isolate them and where possible replace them with a new, fully updated build, hunt for compromise and report anything found, then update. The fixed builds are 14.1-73.37 and 13.1-64.23.

Administrators posting on Reddit, as reported by BleepingComputer, said IT suppliers, CERTs and national cyber agencies had contacted them before disclosure, in at least one case with advice to shut NetScalers down immediately. As reported by The Stack, Citrix’s guidance for any appliance suspected of compromise is to change every service account password and secret stored on it.

AdvertisementZoomInfo
More from The BriefAll briefs
Bytes Technology Group

Bytes lifts its FY27 outlook as costs hold back operating profit

Arctic Wolf

Arctic Wolf opens a sensorless MDR tier to MSPs only

Vectra AI

Vectra AI launches Ascent partner program with three levels

Capgemini

Capgemini sees $230bn of bank payments revenue at risk from stablecoins

Get the briefs every week in The VETTDD Briefing.