Citrix NetScaler flaw is already being exploited, CISA confirms, and the patch window is days not weeks

A critical bug in NetScaler ADC and Gateway lets attackers run commands without logging in - the catch is US federal agencies have been given just three days to sort it, which tells you how bad this really is.

A close up of a padlock on a door
Photo · Kaffeebart / Unsplash

A newly disclosed vulnerability in Citrix’s NetScaler ADC and NetScaler Gateway products has been rated critical, and - more importantly - is already being used by attackers in the wild, according to the US Cybersecurity and Infrastructure Security Agency (CISA).

The flaw, tracked as CVE-2026-88771, scores 9.8 out of 10 on the standard severity scale. That number alone means little without context, but the detail that matters here is simpler: CISA has added it to its Known Exploited Vulnerabilities catalogue, which only happens when there’s evidence of real-world attacks, not just theoretical risk.

What the bug actually does

NetScaler ADC and NetScaler Gateway are pieces of infrastructure that sit at the edge of a network, handling application delivery and remote access - the sort of kit that’s deliberately exposed to the internet so staff can log in from home or so web traffic gets load-balanced correctly. That exposure is precisely what makes this bug dangerous.

CISA describes it as an improper input validation vulnerability that lets an unauthenticated attacker execute arbitrary commands. In plain terms: someone doesn’t need a username, a password, or any prior access to the system. If a NetScaler device is running a vulnerable version and is reachable from the internet, an attacker can potentially take control of it remotely.

Citrix has confirmed the issue affects specific version ranges of ADC, including builds before 14.1-73.37 and before 13.1-64.23, plus certain FIPS-certified builds, and has published fixed versions along with guidance in its own advisory.

So who is actually at risk

This is not a consumer bug. NetScaler is enterprise networking gear, bought and configured by IT teams at businesses, universities and government bodies - not something sitting on a home router or a personal laptop. If you don’t run a business network with Citrix appliances, this doesn’t touch you directly.

But if your organisation does use NetScaler ADC or Gateway, the risk is real and current, not hypothetical. CISA’s own compliance deadline for US federal agencies is telling: the vulnerability was added to the catalogue on 27 September 2026 with a remediation due date of just 30 September - a three-day turnaround that agencies are usually given for issues already under active attack, not routine patching cycles. CISA has also flagged that “forensic triage” is required under its own directives, which is agency-speak for: don’t assume a patch alone fixes things, check whether you’ve already been compromised.

Whether this is linked to ransomware specifically is, per CISA’s own listing, currently marked “unknown” - so treat claims of a particular attack campaign with caution until confirmed.

What to do about it

If you’re an ordinary reader, there’s nothing to install and nothing to worry about on a personal device. This is entirely a matter for network administrators and IT security teams running Citrix infrastructure.

For those teams, the advice from both Citrix and CISA is unambiguous: patch to the fixed builds immediately, and don’t treat this as a “get to it next sprint” item. Given the exploitation is already confirmed rather than theoretical, organisations running affected versions should also check logs for signs of prior compromise, not just apply the update and move on.

For everyone else, this is a reminder of a familiar pattern - critical infrastructure software sitting at the internet’s edge remains one of the most attractive targets around, precisely because it’s built to be reachable.

Sources