Two Critical Citrix Flaws Let Hackers Take Control Of Network Devices

Citrix NetScaler Vulnerabilities Let Hackers Take Control of Network Devices | CyberPro Magazine

Key Takeaways:

  • Citrix confirmed two critical Citrix NetScaler vulnerabilities, or zero-day flaws, that can allow attackers to run code remotely.
  • IT professionals were urgently warned to shut down vulnerable network devices.
  • Citrix released emergency software updates to protect systems from attacks.

Citrix confirmed on September 27 that attackers without login credentials had exploited two critical NetScaler flaws around the world. The company issued urgent warnings and emergency updates to help prevent attackers from taking control of systems across corporate networks.

Citrix Confirms Critical Zero-Day Flaws

Citrix confirmed that two critical Citrix NetScaler vulnerabilities, affecting NetScaler ADC and NetScaler Gateway appliances, were being used in cyberattacks before official fixes were available. 

The company published security bulletins for CVE-2026-88771 and CVE-2026-88772. Both flaws received a critical CVSS score of 9.5 out of 10.

These network devices sit at the edge of company networks and handle tasks such as virtual private network connections, remote access, traffic distribution, and user login checks for organizations around the world.

The first flaw, CVE-2026-88771, is caused by the software not properly checking input. An attacker who does not need to log in can use it to run commands on an affected system without needing additional features enabled.

The second flaw, CVE-2026-88772, is a memory overflow issue among Citrix NetScaler vulnerabilities that can allow remote code execution or cause service problems on NetScaler Gateway appliances using Datagram Transport Layer Security.

Administrators Receive Urgent Private Warnings

Before Citrix released its official security notice, some system administrators received urgent private warnings from IT suppliers and security teams telling them to shut down their NetScaler appliances immediately. The first alerts did not include many technical details, but they caused concern across company IT teams and online security forums.

watchTowr, a cybersecurity research firm, also issued public warnings after confirming credible reports that several unpatched flaws allowing remote code execution were being used in real attacks.

The warnings led many organizations to take their network devices offline to reduce the risk of attacks. 

IT professionals shared their experiences as they worked to protect their systems. National emergency response teams and cybersecurity agencies were also watching the situation as attackers searched the internet for vulnerable servers.

Citrix Releases Emergency Software Updates

Citrix released official software updates following the disclosure of the Citrix NetScaler vulnerabilities and urged customers to update their self-managed NetScaler systems as quickly as possible. The company said organizations using affected software versions should install the emergency fixes immediately to reduce the risk of further attacks.

IT professionals without automatic update tools were advised to contact Citrix support for help securing their systems.

Security experts also recommend checking server logs for unusual requests, changing service account passwords, and making sure management interfaces cannot be reached from the public internet. Because attackers may have kept access gained before the updates were installed, high-risk organizations are also advised to carry out detailed checks of their systems.

Taking these steps can help protect company networks from continued attacks and unauthorized access.

Visit CyberPro Magazine For The Most Recent Information.

LinkedIn
Twitter
Facebook
Reddit
Pinterest