Web_Logo
Remote Support
Security Alert: Citrix NetScaler Flaws Under Active Attack
Home » Security Alerts  »  Security Alert: Citrix NetScaler Flaws Under Active Attack

Security Alert: Citrix NetScaler Flaws Under Active Attack

Attackers are actively exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway, the appliances many businesses use for remote access and VPN. The US cyber agency CISA issued an urgent alert on 27 September 2026.

  • What it is: Two critical vulnerabilities (CVE-2026-88771 and CVE-2026-88772, both rated 9.5 out of 10) that let an attacker run commands or take over the device without needing a password.
  • Who is affected: Any business running NetScaler ADC or Gateway, including those used for VPN or remote desktop access, on versions older than 14.1-73.37 or 13.1-64.23.
  • The risk: A compromised appliance can give criminals a doorway into your internal network, staff credentials and business data.
  • What to do: Update to the fixed firmware straight away. If your device may already have been exposed, treat it as compromised: change passwords and keys, replace certificates and have it checked or rebuilt.

We recommend that businesses using Citrix NetScaler contact their IT provider today to confirm the device is patched. If you are unsure, get in touch with OzComm and we will check it for you.

Sources: CISA alert | The Hacker News