On September 27, 2026, Citrix issued a security bulletin. It detailed 8 vulnerabilities impacting customer-managed Citrix NetScaler ADC and Gateway products. Notably, two critical unauthenticated Remote Code Execution (RCE) flaws were identified. Citrix confirmed active exploitation of these two critical vulnerabilities in the wild.
On September 27, 2026, Citrix issued a security bulletin. It detailed 8 vulnerabilities impacting customer-managed Citrix NetScaler ADC and Gateway products. Notably, two critical unauthenticated Remote Code Execution (RCE) flaws were identified. Citrix confirmed active exploitation of these two critical vulnerabilities in the wild.
CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.
