Active NetScaler attacks put corporate network edges at risk
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 28th, 2026.
Corporate remote access and application delivery are at immediate risk because attackers are exploiting two critical Citrix NetScaler weaknesses. One can let an unauthenticated attacker run arbitrary commands across affected NetScaler ADC and Gateway deployments. The other can enable code execution or denial of service when DTLS is enabled, which is the default on V P N virtual servers. Citrix released fixes for eight issues in total and confirmed exploitation across unmitigated customer environments.
A compromise at the network edge may expose applications, credentials, and routes into internal systems. Customer-managed appliances and Secure Private Access Hybrid deployments using NetScaler instances are affected. Citrix-managed cloud services are being updated by the provider.
Leaders should treat downtime planning and incident assessment as one coordinated business decision. Defenders need to patch every affected node, verify the running build, and investigate internet-facing appliances for signs of earlier compromise. Patching closes the entry point, but it doesn’t remove persistence an attacker may already have established. Upgrade affected appliances immediately and run a compromise assessment on every internet-facing instance.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.