Back to blog

Blog Post

Beacon: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Share on social

Oct 1, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Beacon: Citrix confirms two NetScaler RCE zero-days exploited in attacks

This story appeared in our weekly cybersecurity newsletter Beacon. Sign up to get weekly updates on the latest news, findings and insights, straight to your inbox every Thursday at 10AM.

Top Story This Week:

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has released emergency security updates for eight vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateways, including two critical zero-days that are already being exploited in the wild.

CVE-2026-88771 and CVE-2026-88772 both carry a CVSS score of 9.5 and can allow unauthenticated remote code execution. The first affects the default configuration, while the second can be exploited when DTLS is enabled, which Citrix says is the default for VPN virtual servers.

Security researchers warned of active exploitation on September 26, before Citrix published its advisory and fixes on September 27. CISA has since added both vulnerabilities to its Known Exploited Vulnerabilities catalogue, while the UK's NCSC is urging organizations to mitigate them promptly. For organizations running NetScaler at the network edge, this meant the window for action opened before the usual vulnerability management process had all the information it normally relies on.

Why it Matters

NetScaler sits directly on the boundary between an organization and the internet, often providing VPN, remote access, authentication and application delivery. A vulnerability that provides unauthenticated RCE in that position can therefore give an attacker a valuable route into the environment. Public reporting suggests that attackers use the vulnerabilities to plant webshells and that exploitation has run globally for weeks.

The timing is significant. Defenders were told NetScaler was being exploited before there was a CVE number, vendor advisory or patch to work from. A process that waits for those inputs leaves teams reacting after exploitation has begun.

When the first sign of a vulnerability is an attacker already exploiting it, knowing what you have exposed is where an effective response starts.

What this Means for Practitioners

Identify affected NetScaler instances. Check all customer-managed NetScaler ADC and Gateway deployments against the Citrix security bulletin, including Secure Private Access Hybrid deployments.

Capture logs and evidence, then patch without delay. As both critical vulnerabilities are being actively exploited, preserve relevant logs and forensic evidence and check affected appliances for signs of compromise. Citrix also provides guidance on checking for the relevant preconditions and indicators of compromise in its advisory.

Apply all recommended remediation. Upgrade to the appropriate fixed build and enable Enhanced ISN Generation to address CVE-2026-88778, which requires a configuration change. If compromise is suspected, rotate credentials, secrets and certificates associated with the appliance and ensure relevant logs are being sent to your SIEM.

What this Means for Security Leaders

The NetScaler incident shows that vulnerability response starts with knowing what is exposed.

When a critical vulnerability emerges, your team needs to move quickly from suspecting a technology may be affected to knowing which internet-facing systems are exposed, what they connect to, who owns them, and how urgently each needs action. That matters most when exploitation begins before a patch exists. Faster patching only helps once a fix is available, whereas a reliable view of your external attack surface helps from the first warning.

That visibility also shapes the decisions that come before a patch. If no fix exists yet, decisions need to made made quickly, and those decisions are far easier when ownership, dependencies and the authority to act are already settled.

Teams that can establish their exposure within hours have time to make those decisions deliberately, and teams that can't are left making them under pressure.

Discover More

How to Outpace Vulnerability Exploits

The window between a vulnerability being disclosed and attackers exploiting it is getting shorter. In this blog, we explore why traditional vulnerability management can leave organizations struggling to keep pace, and how a more proactive approach can help security teams identify and address exposures before they become incidents. Read more.

The Complete Guide to Attack Surface Management

Your external attack surface is constantly changing, with new assets appearing, existing ones changing and forgotten systems becoming potential entry points for attackers. This guide explores how Attack Surface Management helps organizations maintain visibility of their internet-facing assets and identify exposures before attackers can exploit them. Read more.

Weekly News Digest

Cyberattack hits Welsh police force, may have affected staff data  

Dyfed-Powys Police reported disruption to some non-emergency systems and said employee information may have been compromised. The significance of this incident is not necessarily the temporary loss of online services; it is the possibility that an intrusion into a UK police force could provide an attacker with information useful for targeting the people and organizations that underpin policing. If staff data has been compromised, the incident could therefore create a second-order threat.

ShinyHunters hackers say they breached FBI, stole data on bureau employees

‍ShinyHunters claimed to “hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI”, with reports of a 5,000 line sample being shared with journalists and purported to contain details of sensitive job assignments regarding China, Russia and drug cartels. At the time of writing, ShinyHunters have removed all references to the FBI from their dark web leaks site, though their most recently-captured statement on the matter claimed their goals had been achieved - namely the rescinding of several details included in the FBI’s May 2026 alert about the group - and emphasized that it was not their intention to financially extort the agency.

Australia says OpenAI agent hacked government website, checks for more breaches

Australia is investigating an incident in which an OpenAI agent gained unauthorized access to a Medicare health-data portal in June while researching public medical spending. Prime Minister Anthony Albanese said there was no evidence that personal patient information had been accessed, but criticized OpenAI for waiting until September to notify the government. OpenAI said its review found no evidence of patient records being accessed, while Australian authorities are still investigating the breach and whether other government websites were affected.

‍

‍

‍

‍

‍

Tom Duncan

Author

Tom Duncan

Head of Content and Communications in Marketing

Traditional vulnerability management typically works from a known, relatively static asset inventory and scans it on a schedule. ASM starts from the opposite assumption - that unknown assets exist - and continuously discovers the external attack surface rather than relying on what's already catalogued.

Related Blog Posts

September 24, 2026

Beacon: ShinyHunters Hacks Cl0p Leak Site

September 22, 2026

Sentinel integration for Searchlight Threat – Monitor

September 22, 2026

Reduce false positives with Email Format Validation

September 22, 2026

New Company Dashboard in Searchlight Threat – Monitor

September 17, 2026

Beacon: AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

September 16, 2026

How AI Is Collapsing Exploitation Timelines

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient