Skip to content

company

Citrix

Citrix Systems, now part of Cloud Software Group, makes NetScaler ADC/Gateway appliances for application delivery, load balancing, and remote access.

Known aliases

  • Citrix Systems
  • Cloud Software Group

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

NetScaler compromise response has to unwind the controls the gateway concentrated

Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence55
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
security5 publishers

NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week

CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.

Perspective Coverage

5 publishers
Builder
Builder 14%
Operator
Operator 73%
Investor
Investor 13%

Reality

Evidence78
Adoption62
Hype gap+10
Incentives38
Confidence75
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security1 publisher

A signed UEFI shell can disable the Secure Boot that trusted it

On a September 10 podcast, Eclypsium researchers walked from vulnerable signed UEFI shells to Fire Ant binaries wearing EDR agent names. The common thread is verification: a defender can check very little of that stack alone.

Publishers:eclypsium.com

Reality

Evidence30
Adoption30
Hype gap+15
Incentives78
Confidence45

Earlier coverage

  1. Two datasets, one vendor list: edge risk is a procurement problem, not a CVE queue

    Security · August 26, 2026 · 1 publisher