Remote access at risk as Citrix gateways face active attacks

Remote access at risk as Citrix gateways face active attacks. Remote access gateways may already be compromised after attackers exploited two critical NetScaler weaknesses before public fixes were available.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 29th, 2026.

Remote access gateways may already be compromised after attackers exploited two critical NetScaler weaknesses before public fixes were available. One weakness allows unauthenticated code execution in default deployments. The other affects systems with DTLS enabled. CISA added both to its Known Exploited Vulnerabilities catalog, and more than twenty thousand internet-exposed instances were reported as potentially at risk. Confirmed compromises were not described as widespread, but exposure at this scale still demands urgent action.

These appliances sit at the network edge and broker trusted access into internal systems. That makes this an incident-response priority rather than a routine patch cycle. Defenders should preserve evidence, isolate suspected devices, update every node, revoke exposed credentials, and hunt for persistence. Patching closes the known attack paths, but it can’t prove that an appliance was never breached. Exploited edge systems require both remediation and retrospective investigation. Inventory all customer-managed NetScaler systems today, preserve evidence before updating, and escalate suspicious signs to full incident response.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Remote access at risk as Citrix gateways face active attacks
Broadcast by