What Happened
Citrix confirmed on September 27 the active exploitation of two critical NetScaler ADC and Gateway flaws. CVE-2026-88771 allows unauthenticated command execution through improper input validation. CVE-2026-88772 is a buffer overflow reachable when DTLS is enabled, and DTLS is on by default for VPN virtual servers. Both score 9.5 on the CVSS scale. Fixed builds are 14.1-73.37 and 13.1-64.23 or later. CISA gave federal agencies until September 30 to patch and reported confirmed exploitation worldwide. Some IT suppliers told customers to shut appliances down before Citrix published its bulletin. Read the full breakdown from The Hacker News.
Why This Matters for Canadian Organizations
The Canadian Centre for Cyber Security published alert AL26-024 on September 27. It says activity has appeared across multiple Citrix customer environments worldwide and admits the full extent remains unknown. Canadian banks, hospitals, universities, municipalities, and federal departments run NetScaler as their remote access front door. A flaw with no authentication requirement on a device facing the Internet gives an attacker a direct path inside.
The Cyber Centre advice goes beyond patching. It asks teams to preserve logs and diagnostic bundles before making changes, hunt for suspicious processes and connections, and consider taking Internet-facing appliances offline. A patch installed after compromise does not evict an attacker. Canadian operators of designated critical systems under Bill C-26 also face reporting duties if an intrusion is confirmed.
What to Do
Inventory every NetScaler ADC and Gateway in your environment, including forgotten test units and branch appliances. Upgrade to a fixed build immediately. Capture forensic evidence first, then review logs for unusual sessions and new files. If you find signs of compromise, isolate the device, rebuild it from clean firmware, rotate all credentials and encryption keys, invalidate active sessions, and replace SSL certificates. Report matching activity to the Cyber Centre through My Cyber Portal or contact@cyber.gc.ca.
Follow related coverage in our TechTalk section and daily updates in News.






