CISA warns of two critical zero-day flaws in Citrix NetScaler
The flaws allow remote code execution and are already being exploited worldwide, the U.S. cybersecurity agency said.
What we know
- The Cybersecurity and Infrastructure Security Agency said Citrix NetScaler ADC and NetScaler Gateway products are affected by multiple vulnerabilities. [1]
- CISA said two of the flaws are critical zero-day vulnerabilities that allow remote code execution. [1]
- CISA said the vulnerabilities are being exploited globally. [1]
- CISA published an alert on the issue dated September 27, 2026. [2]
- Not yet confirmed: The specific number of affected organizations, who is behind the exploitation, and technical details of the vulnerabilities beyond what CISA described are not stated in the available sources.
The Cybersecurity and Infrastructure Security Agency (CISA) said Citrix NetScaler ADC and NetScaler Gateway products are affected by multiple security vulnerabilities, including two critical zero-day flaws that allow remote code execution. [1]
CISA said in a post on X that the two critical vulnerabilities are already being exploited globally. [1]
The agency pointed to an alert, dated September 27, 2026, with further information on the vulnerabilities. [2]
CISA did not say in its post how many organizations have been affected or identify who is carrying out the exploitation.
RECEIPTS · 2 SOURCES
- 1POST ON X · @CISAgov (Cybersecurity and Infrastructure Security Agency)🚨Citrix NetScaler ADC and NetScaler Gateway are affected by multiple vulnerabilities, including 2 critical zero-day #RCE vulnerabilities beiOpen source ↗ Archived copy
- 2OFFICIAL STATEMENT · go.dhs.govgo.dhs.govOpen source ↗ Archived copy
Update log · Story first publishedChecked against its sources before publishing.Spot an error? Tell us →