
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Security firm watchTowr says two unpatched remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway are being exploited in the wild, while Citrix has neither confirmed the bugs nor released a fix.
What watchTowr says
Security company watchTowr said on September 26 that two new, unpatched vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway allow remote code execution (RCE) and are being actively exploited in the wild. In its first post on X that day the firm wrote that it was reacting to reports of several unpatched NetScaler RCE flaws: "While details are scarce, the information is credible."
A follow-up post at 22:19 UTC gave the fuller account: two vulnerabilities, both unpatched, and exploited before any fix existed. The flaws were found during forensic investigations, and Citrix communications and patches are expected early in the week of September 28. watchTowr published no evidence and named no victim.
The new flaws are not the authentication bypass CVE-2026-19490 that Citrix fixed on August 19 and CISA added to its Known Exploited Vulnerabilities (KEV) catalog on September 9. It is also unclear whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or newer ones are affected.
Administrators take appliances offline
Reports of shutdown advice appeared on Reddit the same day. An administrator posting in r/Citrix wrote that their IT supplier's security team had called to advise shutting their NetScalers down immediately, without giving details; others said their organizations had done the same. With no vendor bulletin there is no workaround or published indicators of compromise. The appliances sit at the edge of enterprise networks, handling VPN and remote access, load balancing and authentication; until a fix ships, operators must decide whether to keep one online, isolate it or power it off.
What defenders can do now
Because the exploitation happened before any fix existed, installing that fix will not show whether an attacker got in first. Last year, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands' National Cyber Security Center said updating alone did not remove the risk, since an attacker could keep access gained before the patch.
Citrix's guidance for a suspected NetScaler compromise starts with preserving evidence (a VPX snapshot, logs from remote syslog servers and NetScaler Console, a support bundle and a core dump). It then advises isolating the appliance, changing every service account password and secret stored on it, resetting the passwords of users who signed in through it, and revoking its certificates and keys; the management interface should never be exposed to the public internet.
It is also unclear which versions will get a fix: NetScaler 13.1 reached End of Maintenance on September 15. As of Sunday morning Citrix had published nothing; The Hacker News asked owner Cloud Software Group and watchTowr for comment.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.