Affected Systems

Citrix NetScaler ADC and NetScaler Gateway appliances configured as AAA virtual servers or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Specific vulnerable versions not disclosed in advisory. Over 22,000 NetScaler ADC and 1,700 Gateway instances exposed online.

Exploitation Status

Active exploitation confirmed. Previdian sensors detected exploitation attempts from Australia, US, and Germany on September 3, 2026, following public release of a credible proof-of-concept exploit. Centre for Cybersecurity Belgium also warned of active targeting.

Business Impact

Unauthenticated remote attackers can bypass authentication on vulnerable NetScaler appliances, gaining unauthorized access to VPN gateways and authentication infrastructure. This enables initial access for ransomware deployment, lateral movement, and data exfiltration. Citrix appliances have been exploited by ransomware gangs in 6 prior incidents. Exploitation attempts observed within 2 weeks of patch release, indicating rapid weaponization. Unknown number of vulnerable instances remain unpatched.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade all Citrix NetScaler ADC and Gateway appliances to the patched builds specified in the August 19, 2026 Citrix security bulletin
  • Prioritize patching appliances configured as AAA virtual servers or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), especially those with SAML Action configured
  • Review NetScaler authentication logs from August 19 onward for anomalous login activity, session creation without valid credentials, or requests matching public PoC patterns
  • Inventory all NetScaler appliances and verify patch status, focusing on internet-facing instances first
  • If immediate patching is not possible, consider temporarily disabling affected Gateway configurations or restricting access via firewall rules until patching is complete