TTO-2026-0927-173 · September 27, 2026 Zero-DayActive ExploitationCritical

Citrix NetScaler Two Zero-Day RCE Vulnerabilities Actively Exploited in Attacks Against Enterprise and Government Networks

citrix.comCVE-2026-62106 CVSS 9.8 unauthenticated RCECVE-2026-62107 CVSS 9.4 authenticated root escalationNetScaler ADC and Gateway affectedTwo CVEs chained in observed attacksCISA KEVEmergency patch released

Summary

Citrix has released emergency patches for two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are being actively exploited in attacks against enterprise and government networks. CVE-2026-62106 is rated CVSS 9.8 and allows unauthenticated remote code execution through the NetScaler management interface. CVE-2026-62107 is rated CVSS 9.4 and allows an authenticated attacker to escalate privileges to root. The two vulnerabilities are being chained in observed attacks: CVE-2026-62106 provides initial unauthenticated access, and CVE-2026-62107 escalates to root, giving attackers full control of the NetScaler appliance. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog.

Timeline

DateEvent
Prior to Sep 26, 2026CVE-2026-62106 and CVE-2026-62107 exploited as zero-days in active campaigns against enterprise and government NetScaler deployments
Sep 26, 2026Citrix releases emergency patches for both CVEs; confirms active exploitation; CybersecurityNews reports full technical details
Sep 26-27, 2026CISA adds both CVEs to KEV catalog; TTO-2026-0927-173 published

What Happened

NetScaler ADC and NetScaler Gateway are Citrix’s network appliance products for load balancing, SSL offloading, and secure remote access. NetScaler Gateway is widely deployed as the primary VPN and remote access gateway for enterprise and government organizations — an internet-facing appliance reachable by unauthenticated attackers from the public internet.

CVE-2026-62106 is a memory corruption vulnerability in the NetScaler management interface’s HTTP request handling. The interface fails to validate the length of certain HTTP header values, allowing an unauthenticated attacker to send a specially crafted request that triggers a heap-based buffer overflow exploitable for remote code execution. In observed exploitation, attackers have used this initial foothold to deploy a web shell on the NetScaler appliance for persistent access.

CVE-2026-62107 is a privilege escalation vulnerability in NetScaler’s configuration management subsystem. An attacker with any authenticated access — including through a web shell established via CVE-2026-62106 — can exploit a command injection flaw to escalate privileges to root. Root access on a NetScaler appliance provides full visibility into all traffic passing through the appliance, all SSL private keys and certificates, all session tokens and authentication cookies in transit, all VPN credentials and session data, and the ability to modify appliance configuration to intercept or redirect traffic. Citrix Bleed in 2023 demonstrated how NetScaler session token theft alone could compromise major organizations without triggering authentication alerts; root access provides capabilities well beyond session token theft.

Administrators should apply the emergency patch immediately, restrict management interface access to trusted IP ranges, audit the appliance for unexpected files or processes indicating web shell presence, and rotate all certificates whose private keys were stored on or accessible from the NetScaler appliance during the vulnerable period.

Domain Intelligence

citrix.com — 87.0

citrix.com scores at 87.0 in the high-trust range — the same tier as checkpoint.com. Citrix is the vendor of the affected NetScaler ADC and Gateway products and the party that patched CVE-2026-62106 and CVE-2026-62107 and published remediation guidance. The T6_CONSUMER_REPUTATION_PENALTY flag reflects consumer-facing reputation signals rather than infrastructure deficiencies.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 27, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026