Two critical NetScaler vulnerabilities are under active attack, and Canadian organizations need to respond quickly. On September 27, 2026, the Canadian Centre for Cyber Security issued an urgent alert about flaws in Citrix NetScaler ADC and NetScaler Gateway. Because these appliances often sit at the network edge, a single compromised box can open the door to your entire internal network.
In this post, we explain what happened, who is affected and, most importantly, what your team should do this week.
What Happened Over the Weekend
The story moved fast. Late last week, administrators began reporting on Reddit that IT suppliers were urging them to shut down their NetScaler appliances. According to BleepingComputer, some said law enforcement, CERTs and national cyber agencies had also reached out.
Then, on Sunday, Citrix published security bulletin CTX697096. The update fixes eight flaws, tracked as CVE-2026-88771 through CVE-2026-88778. Crucially, Citrix confirmed that attackers exploited two of them as zero-days. In its bulletin, the company said “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.”
Shortly after, the Canadian Centre for Cyber Security published alert AL26-024. The Cyber Centre noted that attackers have hit multiple Citrix customer environments worldwide. However, the full extent of the activity is still unknown.
Understanding the Two Exploited NetScaler Vulnerabilities

Let’s look at each flaw in plain terms.
CVE-2026-88771 is an improper input validation issue. It lets a remote, unauthenticated attacker execute arbitrary commands on a vulnerable appliance. According to BleepingComputer, it affects deployments running the default configuration. Moreover, it does not require any additional feature. It carries a severity score of 9.5.
CVE-2026-88772 is a memory overflow issue. It can lead to remote code execution or a denial-of-service condition. This one only works when DTLS is turned on. Unfortunately, Citrix notes that DTLS is enabled by default on VPN virtual servers. It also scores 9.5.
Importantly, attackers can exploit the two flaws independently. As a result, both NetScaler vulnerabilities need attention at the same time.
Which Deployments Are Affected
The bulletin applies to customer-managed appliances. Specifically, the affected versions are:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC FIPS before 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP before 13.1-37.279
In addition, the flaws affect Secure Private Access Hybrid deployments that use NetScaler instances. On the other hand, the bulletin does not cover Citrix-managed cloud services. Cloud Software Group is upgrading those services itself.
Why These Attacks Deserve Serious Attention
These NetScaler vulnerabilities are not a routine patch cycle. According to Help Net Security, researcher Kevin Beaumont said the attacks have been unfolding all month. He described the activity as “probably nation state aligned,” focused on espionage.
Furthermore, Beaumont warned that the webshells are unique to each box. The attackers also ran anti-forensics commands to delete artefacts. Consequently, a clean-looking appliance is not proof of safety.
Meanwhile, Tenable’s Satnam Narang offered useful context. Based on Tenable’s research, roughly two-thirds of threat actor activity against NetScaler over seven years involved advanced persistent threat groups. The remaining third involved ransomware groups and their affiliates.
In the United States, CISA added both flaws to its Known Exploited Vulnerabilities catalog on Sunday. It ordered federal civilian agencies to address them by September 30.
A Practical Response Plan for NetScaler Vulnerabilities

So, what should Canadian IT teams do? Based on the Cyber Centre alert and vendor guidance, we recommend the following steps.
- Inventory your appliances. Identify every NetScaler ADC and Gateway, especially Internet-facing ones. Then confirm their exact builds.
- Preserve evidence first. The Cyber Centre advises preserving forensic evidence before rebooting, patching or rebuilding, where feasible. Keep appliance logs, remote syslog records and NetScaler Console logs.
- Patch without delay. Upgrade to the fixed builds listed above. Citrix advises customers to upgrade, then check for evidence of compromise.
- Hunt for compromise. Review running processes, network connections, startup scripts and web directories. Also check crash dump locations for signs of persistence.
- Check older logs. Citrix’s detection script only works if logs have not rotated since the attack. Therefore, search your SIEM data as well.
- Plan for the worst. If you suspect compromise, reset credentials, invalidate sessions and replace certificates. Be ready to rebuild appliances from known-good configurations.
Notably, the Dutch NCSC advised backing up memory and log files going back at least a month before installing updates. It also recommended monitoring devices even after the upgrade.
If you cannot patch immediately, the Cyber Centre suggests weighing a temporary shutdown of Internet-facing appliances. Of course, that decision depends on your own risk assessment and business needs.
Reporting and Next Steps for Canadian Organizations
If you find activity matching the alert, the Cyber Centre encourages reporting through My Cyber Portal or by email to contact@cyber.gc.ca. Reporting helps protect other Canadian organizations too.
Beyond these NetScaler vulnerabilities, the alert is a reminder to follow the Cyber Centre’s Top 10 IT Security Actions. For instance, consolidate and monitor Internet gateways, patch quickly and isolate web-facing applications.
Edge devices remain a favourite target because they sit between the Internet and your core systems. In short, treating them as critical assets is no longer optional.
Need help assessing your exposure or planning a secure upgrade? Our team supports businesses with networking, cybersecurity and incident readiness. Visit Karavi to learn more about our IT services.


No comment