#rce
505 posts · Last used 8d
If you're running Netscaler suggest you reach out to your support partner or open a case directly with Citrix for more information ASAP. Something's brewing.
Comms sent out by the National Cyber Security Center (NCSC):
CONTEXT:
This is a pre-notification regarding two zero-day vulnerabilities in Citrix NetScaler. Due to the potential impact of successful exploitation and the likelihood that malicious actors will attempt to exploit these vulnerabilities, the Dutch National Cyber Security Centre (NCSC) has decided to issue a pre-notification.
Citrix expects to release patches early next week. Because updating Citrix NetScaler appliances can be complex and may result in downtime, the NCSC wants to give organizations the opportunity to take these vulnerabilities into account, implement appropriate measures where possible, and prepare to install the patches as quickly as possible once they become available.
FACTS:
- The NCSC received information from a European partner CERT regarding two zero-day vulnerabilities in Citrix NetScaler.
- These are two critical zero-day vulnerabilities in Citrix NetScaler, each of which can independently lead to Remote Code Execution (RCE). One of the vulnerabilities allows shellcode to be placed in memory. The technical details of the second vulnerability are still under investigation.
- No CVE numbers are currently known for either vulnerability, and Citrix has not yet published an advisory. Citrix has stated that it is working to release patches as soon as possible and expects to publish them early next week.
- Further information, such as Indicators of Compromise (IoCs), is not available at the time of writing. The NCSC is in contact with Citrix to obtain additional information about the vulnerabilities and possible IoCs while awaiting the patches.
- The zero-day vulnerabilities were discovered during an investigation by Citrix at customer environments following reports of disruptions. The investigation identified exploitation, after which Citrix submitted a notification under the Cyber Resilience Act (CRA).
- The NCSC received the notification under the Cyber Resilience Act (CRA), which has been in effect since 11 September 2026.
- Under this regulation, manufacturers have mandatory reporting obligations. This may result in the NCSC receiving reports that are not yet complete, for example because the vendor's investigation is still ongoing. More information about the CRA is available on the NCSC website.
ASSESSMENT:
- The NCSC expects that exploitation attempts may increase once Citrix publishes the patches and additional technical information.
- Exploitation has been identified at multiple Citrix customers worldwide. The NCSC does not currently know whether these zero-day vulnerabilities are being exploited on a widespread scale.
- One of the vulnerabilities involves placing shellcode in memory. Similar techniques have previously been observed with critical Citrix NetScaler vulnerabilities. For example, in August 2026 researchers described how a Citrix NetScaler vulnerability could be used to execute shellcode directly from memory and thereby execute code on the system.
- Due to the potential impact of successful exploitation and the likelihood that malicious actors will attempt to exploit these vulnerabilities, the NCSC has decided to inform relevant organizations in advance. This allows organizations to take the vulnerabilities into account and respond quickly once Citrix releases additional information and patches.



![Krytyczna luka w Linux KVM na ARM64. W określonych warunkach można przejąć kontrolę nad hostem [CVE-2026-89775]](https://sekurak.pl/wp-content/uploads/2023/08/hackerzzz.jpeg)





