Summary
Citrix has released emergency patches for two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are being actively exploited in attacks against enterprise and government networks. CVE-2026-62106 is rated CVSS 9.8 and allows unauthenticated remote code execution through the NetScaler management interface. CVE-2026-62107 is rated CVSS 9.4 and allows an authenticated attacker to escalate privileges to root. The two vulnerabilities are being chained in observed attacks: CVE-2026-62106 provides initial unauthenticated access, and CVE-2026-62107 escalates to root, giving attackers full control of the NetScaler appliance. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 26, 2026 | CVE-2026-62106 and CVE-2026-62107 exploited as zero-days in active campaigns against enterprise and government NetScaler deployments |
| Sep 26, 2026 | Citrix releases emergency patches for both CVEs; confirms active exploitation; CybersecurityNews reports full technical details |
| Sep 26-27, 2026 | CISA adds both CVEs to KEV catalog; TTO-2026-0927-173 published |
What Happened
NetScaler ADC and NetScaler Gateway are Citrix’s network appliance products for load balancing, SSL offloading, and secure remote access. NetScaler Gateway is widely deployed as the primary VPN and remote access gateway for enterprise and government organizations — an internet-facing appliance reachable by unauthenticated attackers from the public internet.
CVE-2026-62106 is a memory corruption vulnerability in the NetScaler management interface’s HTTP request handling. The interface fails to validate the length of certain HTTP header values, allowing an unauthenticated attacker to send a specially crafted request that triggers a heap-based buffer overflow exploitable for remote code execution. In observed exploitation, attackers have used this initial foothold to deploy a web shell on the NetScaler appliance for persistent access.
CVE-2026-62107 is a privilege escalation vulnerability in NetScaler’s configuration management subsystem. An attacker with any authenticated access — including through a web shell established via CVE-2026-62106 — can exploit a command injection flaw to escalate privileges to root. Root access on a NetScaler appliance provides full visibility into all traffic passing through the appliance, all SSL private keys and certificates, all session tokens and authentication cookies in transit, all VPN credentials and session data, and the ability to modify appliance configuration to intercept or redirect traffic. Citrix Bleed in 2023 demonstrated how NetScaler session token theft alone could compromise major organizations without triggering authentication alerts; root access provides capabilities well beyond session token theft.
Administrators should apply the emergency patch immediately, restrict management interface access to trusted IP ranges, audit the appliance for unexpected files or processes indicating web shell presence, and rotate all certificates whose private keys were stored on or accessible from the NetScaler appliance during the vulnerable period.
Domain Intelligence
citrix.com — 87.0
citrix.com scores at 87.0 in the high-trust range — the same tier as checkpoint.com. Citrix is the vendor of the affected NetScaler ADC and Gateway products and the party that patched CVE-2026-62106 and CVE-2026-62107 and published remediation guidance. The T6_CONSUMER_REPUTATION_PENALTY flag reflects consumer-facing reputation signals rather than infrastructure deficiencies.
The Trust Observatory · thetrustobservatory.com · September 27, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026