Exploit

CISA Confirms Critical Zero-Day Exploits in Citrix NetScaler ADC and Gateway

September 29, 2026

Cybersecurity

Exploit

Key Facts

Signal Type

Exploit

Industry

Cybersecurity

Companies

Citrix, CISA, National Cybersecurity Centre of the Netherlands

Date

September 29, 2026

What Happened

On September 26, 2026, CISA announced the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler: CVE-2026-88771 and CVE-2026-88772, each with a CVSS score of 9.5. These flaws allow remote code execution and affect all default configurations of NetScaler ADC and Gateway. Citrix issued security updates on September 27, but exploitation had already begun before patches were available.

The vulnerabilities stem from improper input validation and a buffer overflow. The National Cybersecurity Centre of the Netherlands also alerted local organizations based on information from a European CERT, broadening the geographic impact beyond the United States.

Who Is Affected

Any organization using Citrix NetScaler ADC or Gateway in a default configuration is at immediate risk. This includes enterprises, government agencies, and service providers globally, as exploitation was confirmed by CISA and highlighted by the Netherlands NCSC. Vulnerabilities were already exploited before patches were released, meaning unpatched systems are likely compromised.

Market Impact

  • Urgent remediation demand: Security vendors, MSSPs, and incident-response firms can target NetScaler-dependent accounts with tailored patch and forensics outreach.
  • Expanded addressable market: European organizations alerted by the Netherlands NCSC represent a fresh cross-border sales trigger.
  • High-severity events drive decision-making: CVSS 9.5 zero-days with active exploitation shorten buying cycles for security solutions.

What to Watch

Monitor for additional advisories from CISA and Citrix as the full threat graph, including 13 entities and 27 inferred relationships, is tracked. Rapid patch adoption rates among affected organizations will determine whether further exploits emerge. SDRs should ask prospects if they have applied the September 27 updates or require a security assessment.

Related coverage

Get cybersecurity signals in your CRM

Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.

Book a 15 min call
Dominykas Rukas - Revenanas