Two unconfirmed zero-day remote code execution vulnerabilities in Citrix NetScaler are reportedly being actively exploited in the wild, based on a leaked NCSC-NL pre-notification circulated on and confirmed by researchers watchTowr and Kevin Beaumont. No CVEs have been assigned, no formal Citrix advisory exists, and no patches or public proofs-of-concept are available as of September 27. Citrix is reportedly planning patches early the following week. The flaws are unrelated to the previously disclosed CVE-2026-19490 and CVE-2026-19489. NetScaler has historically been a frequent target, with 13 NetScaler-related entries in CISA's KEV catalog, and roughly two-thirds of past exploitation attributed to APT groups.
Questions this post answers
No, as of September 27, 2026, Citrix has not published a formal security advisory and no patches are available. Public reporting indicates Citrix plans to release patches early in the week of September 28, 2026. No CVE IDs have been assigned yet, and no public proof-of-concept exploits exist. Track this developing NetScaler patch timeline on daily.dev before deciding whether to take devices offline.
No, neither CVE-2026-19490 nor CVE-2026-19489 appears related to the newly reported zero-days. Both are previously disclosed NetScaler ADC and Gateway vulnerabilities with existing patches; CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities catalog on September 9, 2026, but is a distinct issue from the unpatched flaws now under active exploitation. Follow how this new zero-day differs from prior NetScaler CVEs on daily.dev while patch details emerge.
Details first surfaced on September 25, 2026, through a post on r/Citrix citing a pre-notification reportedly from the Dutch national cyber security center (NCSC-NL), distributed under Traffic Light Protocol AMBER+STRICT restrictions. Researchers watchTowr and Kevin Beaumont subsequently confirmed on September 26 that active exploitation was occurring, though no vendor advisory had been issued. Watch for the official Citrix advisory on daily.dev to confirm details currently circulating from leaked sources.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
