“NetScaler” — 35 distilled results

Citrix NetScaler critical vulnerabilities actively exploited

Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway products are being actively exploited as of late September 2026, including CVE-2026-88771 (command injection) and CVE-2026-19490 (SAML authentication bypass). Citrix released security bulletins and patches are available.

Citrix patches exploited NetScaler zero-day vulnerabilities

Citrix released patches on September 27, 2026, for two critical remote-code-execution zero-day flaws (CVE-2026-88771, CVE-2026-88772) in NetScaler ADC and Gateway that researchers confirmed are being exploited globally. CISA set a deadline for organizations to apply updates.

CISA warns of active exploitation of critical infrastructure flaws

Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.