# 2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: CERT-EU
- Category: Vulnerabilities
- Original publication time: 2026-09-27T17:40:52Z
- First observed by NexusTechWire: 2026-10-01T17:27:53Z
- Original source: https://cert.europa.eu/publications/security-advisories/2026-014/
- NexusTechWire record: https://nexustechwire.com/news/news-4f7cf02e8c7473e632a3

## From the publisher

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [CERT-EU](https://cert.europa.eu/publications/security-advisories/2026-014/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
