TORCH DAILY
LATESTDaily updates from every desk, with their sourcesWatch →

CISA warns of two critical zero-day flaws in Citrix NetScaler

The flaws allow remote code execution and are already being exploited worldwide, the U.S. cybersecurity agency said.

What we know

  1. The Cybersecurity and Infrastructure Security Agency said Citrix NetScaler ADC and NetScaler Gateway products are affected by multiple vulnerabilities. [1]
  2. CISA said two of the flaws are critical zero-day vulnerabilities that allow remote code execution. [1]
  3. CISA said the vulnerabilities are being exploited globally. [1]
  4. CISA published an alert on the issue dated September 27, 2026. [2]
  5. Not yet confirmed: The specific number of affected organizations, who is behind the exploitation, and technical details of the vulnerabilities beyond what CISA described are not stated in the available sources.

The Cybersecurity and Infrastructure Security Agency (CISA) said Citrix NetScaler ADC and NetScaler Gateway products are affected by multiple security vulnerabilities, including two critical zero-day flaws that allow remote code execution. [1]

CISA said in a post on X that the two critical vulnerabilities are already being exploited globally. [1]

The agency pointed to an alert, dated September 27, 2026, with further information on the vulnerabilities. [2]

CISA did not say in its post how many organizations have been affected or identify who is carrying out the exploitation.

RECEIPTS · 2 SOURCES
  1. 1POST ON X · @CISAgov (Cybersecurity and Infrastructure Security Agency)🚨Citrix NetScaler ADC and NetScaler Gateway are affected by multiple vulnerabilities, including 2 critical zero-day #RCE vulnerabilities beiOpen source ↗ Archived copy
  2. 2OFFICIAL STATEMENT · go.dhs.govgo.dhs.govOpen source ↗ Archived copy
Update log · Story first publishedChecked against its sources before publishing.Spot an error? Tell us →
Get the daily brief Sign up

More

Get the daily brief

Follow

We'll email you when there's news. Nothing else.

Unfollow any time. Privacy