Two serious security flaws in Citrix NetScaler remote access and load balancing devices are being actively used by attackers, and Citrix released fixes on 29 September 2026. Businesses that use NetScaler for remote access should act now.
- What it is: Two critical flaws (CVE-2026-88771 and CVE-2026-88772, both rated 9.5 out of 10) let attackers run their own commands on the device without needing a password.
- Who is affected: Organisations running NetScaler ADC or NetScaler Gateway, including versions 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Tens of thousands of devices are exposed to the internet worldwide.
- The risk: Attackers have reportedly been exploiting these flaws for weeks and installing hidden back doors. Installing the patch does not remove a back door that is already in place.
- What to do: Update to the fixed version immediately, keep a backup of device logs and memory, and have your IT provider check for signs of compromise, including unfamiliar files, unexpected admin sessions and unusual outbound connections.
If your business uses NetScaler, we recommend patching today and arranging a compromise check at the same time. Contact OzComm if you would like us to review your environment.
Sources: CISA alert, Palo Alto Networks Unit 42, Help Net Security.