Security · September 29, 2026

Also published in Svenska

Citrix releases patches for two critical zero-day vulnerabilities in NetScaler

Computer screen displaying colorful code
Vishnu Kalanad / Unsplash

Citrix has released software updates to address two critical security flaws in its NetScaler appliances. The company confirmed that these vulnerabilities allow remote code execution and are currently being exploited in the wild. Administrators are advised to apply the patches immediately to secure their networks.

The threat intelligence firm watchTowr issued a warning stating that two distinct weaknesses enable remote code execution. The firm noted that these are unpatched zero-day vulnerabilities that have been discovered during forensic investigations. watchTowr recommended that affected users disconnect their devices from the network to prevent further compromise. This advice aligns with recommendations from government agencies, although Citrix itself did not initially advise shutting down the systems.

Citrix acknowledged the issues and stated that its engineering teams worked continuously to develop a fix. The company released two new versions of the NetScaler operating system to resolve the problems. These updates are available for download on the public NetScaler page, though access is restricted to customers. The new builds are listed on the download site, and administrators should install them as soon as possible to avoid exploitation.

The US Cybersecurity and Infrastructure Security Agency added the vulnerabilities to its list of known exploited vulnerabilities. The agency also issued a separate warning about the flaws. The Dutch National Cyber Security Centre issued a similar alert. The German Federal Office for Information Security had not yet published official information at the time of the report. Citrix published a security advisory that lists several Common Vulnerabilities and Exposures with critical or high severity ratings.

Security researcher Kevin Beaumont verified the authenticity of the vulnerabilities. He stated that the flaws are real and that he had checked the details. A user on Reddit, claiming to be a Citrix customer, reported that the company confirmed the vulnerabilities and that developers were working around the clock to fix them. Citrix has a history of significant security errors in its appliances, with major flaws reported in July and August of the current year. The company is currently working on an official statement regarding the incident.