Two Citrix NetScaler zero-days exploited before a patch existed
Citrix and CISA warned on 27 September that two critical NetScaler flaws allowing remote code execution were already under attack worldwide.
Citrix confirmed on 27 September 2026 that attackers were already exploiting two critical flaws in its NetScaler ADC and NetScaler Gateway network appliances before any fix existed, BleepingComputer reported. Both carry a severity score of 9.5 out of 10 and let an attacker run code on the device. The US Cybersecurity and Infrastructure Security Agency, CISA, warned of active attacks worldwide the same day.
- 2zero-days exploited before Citrix released a fix
- 8NetScaler flaws fixed in Citrix's first bulletin
- 10Citrix vulnerabilities covered by CISA's alert by 9 October
- 4 Octdate CISA added a third, chained flaw to its catalogue
What happened
NetScaler ADC and NetScaler Gateway are appliances that sit at the edge of an organisation's network. They balance traffic between servers and give staff remote access through a virtual private network, or VPN. The first flaw, CVE-2026-88771, comes from improper checking of input. It lets an attacker who has not logged in run commands, and it affects all deployments, including default settings. The second, CVE-2026-88772, is a memory overflow. It can be exploited when DTLS is switched on, which Citrix says is the default for VPN servers.
Warnings spread before the details were public. BleepingComputer reported that administrators on Reddit said their IT suppliers and security teams had privately advised them to shut their NetScaler appliances down immediately, without explaining why. A notice from the Dutch national cyber security centre, NCSC-NL, which circulated online, said Citrix had found the flaws while investigating incidents at several customers. The notice said the information came from a European partner team, and warned that attacks could increase once patches and technical details were released. The agency declined to confirm the notice to BleepingComputer.
Citrix released fixed versions for the supported 14.1 and 13.1 branches, including special builds for government security standards. Its bulletin fixed six other NetScaler flaws at the same time. CISA added the two zero-days to its catalogue of known exploited vulnerabilities on 27 September. It later added a third flaw, CVE-2026-88779, on 4 October, and by 9 October its alert covered ten Citrix vulnerabilities in total, plus a separate bulletin for CVE-2026-107406.
The engineering behind it
Both flaws belong to old, well-known classes of bug. Improper input validation means a program trusts data from outside without checking it fully, so a specially shaped request can make it do something unintended. A memory overflow means the program writes more data into a memory area than it can hold, overwriting nearby memory. The Dutch notice said one flaw let attackers place shellcode, a small piece of attack code, directly into memory. In general, both kinds of bug are made worse when the software is exposed to the whole internet.
DTLS stands for Datagram Transport Layer Security. It is a version of the TLS encryption protocol designed for UDP, a fast network protocol that does not guarantee delivery. VPNs often use it because it handles voice and video traffic well. That convenience also means one more piece of complex code is listening for messages from anyone on the internet, which is where CVE-2026-88772 can be reached.
CISA's update showed how flaws can be chained. CVE-2026-88779 affects appliances set up for SAML, a common single sign-on system, and on its own can crash the device. CISA said that on unpatched devices, an attacker could use it to force a reboot, which could make code planted through CVE-2026-88771 run. One bug that seems only disruptive can therefore help another bug do more harm.
CISA's advice followed a specific order. First, check for signs of compromise, using indicators Citrix provided. Second, send the appliance's logs to a central log system, because local logs rotate quickly and can erase evidence. Third, preserve forensic evidence before updating, because updates can reduce what investigators can see. Then patch quickly. If compromise is suspected, restore a clean backup from before the attack and replace all passwords, encryption keys and certificates.
What it means in Nepal
The sources do not mention Nepal or any Nepali users of NetScaler. The lesson is about the type of device. Any organisation, in any country, that gives staff remote access depends on an edge device like this. Because it faces the internet and sits in front of internal systems, it is a valuable target. If an attacker controls it, they may be able to watch traffic, steal login sessions or move deeper into the network.
The case also shows that patching is not always the first step. Many people assume the right reaction to a security alert is to install the update immediately. CISA's guidance says to look for signs of attack and save evidence first, because an update can remove the traces investigators need. Knowing this order, and why it exists, is part of incident response work in any security operations team. Where patching cannot happen at once, BleepingComputer passed on the advice to reduce the device's exposure to the internet.
Students can use the CISA alert as a study case. It shows how a vulnerability moves from private warnings to public disclosure, catalogue entries, detection rules and later updates over about two weeks. Reading an alert like this, finding the affected versions and writing down the steps an organisation should take is useful practice for a career in networking or security.
What to study if this interests you
Computer Programming, ENCT 101, in the first semester of BCT and BEI, teaches arrays, pointers and input handling in C, where input validation and memory overflows begin. The course has a full guide on this site. Computer Networks, ENCT 304, in the fifth semester of BCT, explains TCP, UDP, routing and VPNs. BEI students meet the same ideas in Telecommunication and Computer Networks, ENEX 352, in the sixth semester.
Network and Cyber Security, ENCT 463, in the eighth semester of BCT, covers encryption protocols such as TLS, firewalls, authentication systems like single sign-on, and incident response. Together these explain both how the attack worked and why CISA asked organisations to collect evidence before patching. A good exercise is to take the CISA alert and write a one-page response plan for a small office that uses a VPN appliance.
Words in this story
- Zero-day
- A security flaw that attackers exploit before the maker has released a fix.
- VPN
- Virtual private network, an encrypted connection that lets staff reach an internal network from outside.
- DTLS
- Datagram Transport Layer Security, a form of TLS encryption made for the UDP network protocol.
- Forensic evidence
- Logs, files and memory records that show what an attacker did, kept so investigators can study the attack.
Where this comes from
- CISA, 27 Sep 2026
- BleepingComputer, 27 Sep 2026
Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.




