Skip to content

project

NetScaler Gateway

Citrix product providing secure remote access and SSL VPN connectivity to corporate networks, deployed as a gateway or AAA virtual server.

Known aliases

  • Citrix Gateway
  • Citrix NetScaler Gateway

Relationships

No evidence-backed relationships are recorded.

Current stories

security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
security5 publishers

NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week

CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.

Perspective Coverage

5 publishers
Builder
Builder 14%
Operator
Operator 73%
Investor
Investor 13%

Reality

Evidence78
Adoption62
Hype gap+10
Incentives38
Confidence75
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74