GetPentest

Eight NetScaler flaws, two already being exploited

September 29, 2026. From issue 8 of The Compliance Brief, one story for teams that commission penetration tests.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

Issue 8 of The Compliance Brief went to subscribers on September 29, 2026. One of its 5 stories bears on exploited vulnerabilities and security testing, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: CISA

Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and CISA added two of them to the Known Exploited Vulnerabilities catalogue. Both are critical zero-days that can each enable remote code execution on their own, and CISA says partner intelligence confirms active exploitation.

Our take, in short

If you terminate remote access or load balancing on NetScaler, stop reading the rest of this email and go check your version. Beyond the immediate patching, a KEV listing has a second life in your sales cycle, because enterprise questionnaires increasingly ask how fast you remediate KEV-listed issues and ask you to prove it with ticket history.

Read the full take on traztech.ca

Also in issue 8

Outside exploited vulnerabilities and security testing, but in the same email:

Older: issue 7 All issues on GetPentest