CERT-EU

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

From Computer Emergency Response Team for the EU institutions ↗

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild.

CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.