Threat Analysis: Citrix Vulnerabilities Under Active Exploitation, Impact on UK SMBs

Threats & Attacks

Threat Analysis: Citrix Vulnerabilities Under Active Exploitation, Impact on UK SMBs

This is your Daily Threat Analysis for 28 September 2026. Today, we examine why the spotlight on Citrix vulnerabilities isn’t something to ignore if you’re involved with UK SMBs.

The NCSC has issued yet another alert urging organizations to mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway. These vulnerabilities have been actively exploited, with attackers leveraging them to gain unauthorised access to networks. The fact we are discussing these vulnerabilities today highlights an age-old problem: organisations often lag in patching systems, despite urgent advisories. The NCSC is clear, if you’ve not patched yet, it’s past time.

ShinyHunters: Renewed Attacks

ShinyHunters, a well-known threat actor group, has launched another wave of attacks, exploiting a vulnerability in Oracle PeopleSoft (CVE-2026-35273). This group has expanded its targeting across sectors, including education, healthcare, and government. What the advisory doesn’t highlight is the group’s previous history of breaching databases and selling data on underground forums. If your organisation uses Oracle systems, particularly PeopleSoft, you’re not safe to assume it won’t happen to you.

Citrix’s Critical Moment

According to The Register, Citrix’s NetScaler has seen a series of critical vulnerabilities. This isn’t the first time, and it won’t be the last. Some may argue these issues should have been spotted and patched ages ago. However, companies continue deploying software solutions without rigorous testing, and attackers repeatedly exploit these gaffes.

From a UK perspective, the exposure isn’t limited to large enterprises. SMBs using Citrix need to rethink their patching strategies immediately. If your IT provider asserts this doesn’t affect you because of your size, ask how many affected businesses during the JLR supply chain breach thought the same.

Wider Impacts and Vendor Responsibility

A broader issue here is the ripple effect of these vulnerabilities across the supply chain. The Cybersecurity and Infrastructure Security Agency (CISA) has also flagged these vulnerabilities. Although some might argue only large enterprises need to worry, the reality is that attackers often exploit smaller firms as entry points to larger targets.

Actionable Steps for SMBs

  1. Prompt Patch Management: Ensure all systems, especially those involving Citrix and Oracle products, are updated with the latest security patches.
  2. Review Vendor Security: Ask tough questions of your software vendors about their patch management policies and historical vulnerability management.
  3. Educate and Train: You cannot defend against what you don’t understand. Train staff to recognise and respond to potential threats.

Before the next item: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.

Sources

NameTitleURL
NCSCExploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gatewayhttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-gateway
The RegisterCertainties in life: Death, taxes, and critical Citrix vulns under attackhttps://www.theregister.com/security/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack/
CISAOrders feds to patch exploited Citrix flaws by Wednesdayhttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
CyberpressShinyHunters Renew PeopleSoft Attackshttps://cyberpress.org/shinyhunters-renew-peoplesoft-attacks/?amp=1
Cloud Google BlogShinyHunters Renewed Exploitation Campaignhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft

Filed under

  • smb-security
  • uk-business
  • vendor-risk
  • incident-response
  • public-sector-security