Skip to main content

Neotech Cloud Solutions

Home/Cybersecurity/Citrix NetScaler zero-days: what happened and what it means for your business

Citrix NetScaler zero-days: what happened and what it means for your business

It’s one of the biggest cybersecurity stories of the week. Two critical flaws in Citrix NetScaler ADC and NetScaler Gateway appliances were exploited by attackers for weeks before they were made public. These products are mostly used by mid-size and large organizations: governments, financial institutions, universities, telecoms, large firms and service providers. Most small businesses don’t run them in-house.

So why write about it here? Because this story shows how a flaw at a “big player” can ripple out to everyone around it, and because it holds a few simple lessons any business can apply.

What happened

On September 27, 2026, Citrix published a security bulletin covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited before disclosure (so-called “zero-days”). Some researchers have nicknamed them “PitScaler.”

  • CVE-2026-88771 lets a remote attacker with no password run code on the appliance. It affects deployments in the default configuration.
  • CVE-2026-88772 is a memory overflow that can lead to code execution or an outage when DTLS is enabled, which it is by default on VPN servers.

The same day, the Canadian Centre for Cyber Security issued alert AL26-024, aimed at IT professionals and managers. In the United States, CISA added both flaws to its Known Exploited Vulnerabilities catalog and ordered federal agencies to secure their appliances by September 30, according to BleepingComputer.

Who is affected

According to Mandiant (Google), the attacks began at least in early September. The earliest known exploitation dates back to September 3, researchers told CyberScoop. Targeted organizations are in North America and Europe, in government, financial services, education, telecom, legal and professional services. Mandiant Consulting’s CTO said the firm is aware of “dozens” of impacted organizations and attributed the attacks to advanced, suspected state-sponsored threat actors.

The attackers planted backdoors (web shells) on the appliances, including two new malware families named WHIPSHOT and SLAPSHOT. They used them to move into internal networks and steal credentials, as BleepingComputer details. The Shadowserver Foundation tracks more than 23,000 IP addresses with NetScaler fingerprints exposed online, though it’s unclear how many are already patched.

Worth noting: Citrix says the bulletin applies to customer-managed appliances. Citrix-managed cloud services are updated by Citrix.

Why it matters

NetScaler appliances are “front door” devices. They sit on the Internet and give access to applications and internal networks, usually without the advanced endpoint protection (EDR) a laptop would have. A flaw there can hand over a key to everything behind it, and go unnoticed for a long time: at least three weeks in this case.

It’s also part of a bigger trend. According to Google, flaws in these edge devices (VPN gateways, firewalls) made up 48% of enterprise-focused zero-days last year, CyberScoop reports. Mandiant now expects “broad and opportunistic exploitation” by other groups.

What an SMB can take from this

Even if you don’t use Citrix, here are three useful habits:

  1. Think about your suppliers and partners. Your accounting firm, your hosted software provider or a large client may run this kind of equipment. If one of them is hit, your data or your exchanges with them could be affected too. Watch for their communications in the coming weeks, and be extra careful with unusual emails that seem to come from them.
  2. Ask your IT provider or hosting company whether they use these products. If you reach a hosted application or remote desktop through a Citrix portal, ask plainly: “Are you affected by CVE-2026-88771 and 88772, and have you applied the fixes?” A good partner will give you a clear answer.
  3. Patch your own equipment quickly. The lesson applies to your own gear too: firewalls, VPNs, routers, servers exposed to the Internet. When a vendor announces an actively exploited flaw, think hours or days, not weeks. Keep an inventory of what faces the Internet and who is responsible for updating it.

And if personal information (clients, employees) is ever affected by an incident at a supplier, remember that Quebec’s Law 25 requires you to document confidentiality incidents. The Commission d’accès à l’information (in French) explains the steps.

At NeoTech Cloud Solutions, we help Greater Montreal SMBs with cybersecurity and managed IT, remotely, in English and French. See our cybersecurity services and our cyber monitoring.

Take stock with a free cyber check

Not sure what your business exposes to the Internet, or what your suppliers rely on? In one short meeting, we’ll review your remote access, updates and backups, and you’ll walk away with a clear list of priorities. No jargon, no commitment.

👉 Book your free cyber check

Prefer to talk to us directly? Call 438-476-2322 or email info@neotechcloudsolutions.com.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *