Skip to content
Frequently asked questions about reported Citrix NetScaler zero

Frequently asked questions about reported Citrix NetScaler zero

Tenable •Satnam Narang • September 27, 2026

There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time.

Reports indicate that there are two critical zero-day vulnerabilities in Citrix NetScaler.

The reports originate from a pre-notification sent out ahead of public disclosure, so there are currently no specific details these flaws and no patches available.

This post will be updated as new information becomes available.

Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding two reported zero-day vulnerabilities in Citrix NetScaler that sources say were actively exploited in the wild. The following FAQ is based on limited public information. This post will be updated with additional details once more information becomes public over the week.

What is the source of the NetScaler vulnerabilities?

On September 25, 2026, reports surfaced through a post on r/Citrix regarding advice to shut down “Netscalers.” This included a report from a user that said this information came from the “Dutch national cyber security center” and further details included a note two zero-day vulnerabilities.

On September 26, 2026, additional reports confirming the existence of these flaws became public, including social posts from researchers at watchTowr on X , as well as Kevin Beaumont on Mastodon.

What is the context surrounding the National Cyber Security Centre (NCSC-NL) alert?

The post on r/Citrix cited details from an NCSC-NL pre-notification that had not yet been made public. Community members in that thread said the pre-notification was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions. Tenable's RSO has not independently obtained or reviewed the contents of this notification.

Has Citrix confirmed the presence of zero-day vulnerabilities?

As of September 27, a formal security advisory from Citrix has not been published.

What are these zero-day vulnerabilities?

Based on public reporting as of September 27, there are reportedly two zero-day vulnerabilities in Citrix NetScaler devices that can lead to remote code execution (RCE):

watchTowr confirmed details for both on September 26, 2026:

We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are… — watchTowr (@watchtowrcyber) September 26, 2026

We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are…

— watchTowr (@watchtowrcyber) September 26, 2026

Are these zero-day vulnerabilities related to CVE-2026-19490 and CVE-2026-19489?

No. Neither CVE-2026-19490 nor CVE-2026-19489 appears to be related. Both are previously disclosed vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway for which patches are available. CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026.

Reports say these vulnerabilities were exploited. How widespread are the attacks?

Based on public reporting, it has not been determined whether exploitation has reached widespread scale. On September 26, Kevin Beaumont stated : “The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.”

How many Citrix NetScaler vulnerabilities have been exploited in the wild in the past?

Citrix NetScaler devices have historically been a popular target for attackers. Including CVE-2026-19490, as of September 27, 2026, there were 13 NetScaler-related entries in CISA's KEV catalog and 24 entries for Citrix products overall. The RSO team has covered several notable incidents:

Which threat actors are exploiting these vulnerabilities?

No details threat actors have been made public at this time. However, based on our research, roughly two-thirds of threat actor activity targeting Citrix NetScaler over the last seven years involved advanced persistent threat (APT) groups, while one-third involved ransomware groups and their affiliates.

Is there a proof-of-concept (PoC) available for these vulnerabilities?

As of September 27, 2026, there are no public proofs-of-concept (PoCs) for these vulnerabilities.

Are patches or mitigations available?

As of September 27, a formal security advisory from Citrix has not been published as of this writing and no patches are currently available. However, public reporting indicates that Citrix plans to release patches early in the week of September 28, 2026.

Are there any indicators of compromise for these vulnerabilities?

There are currently no indicators of compromise (IoCs) publicly available.

Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?

No. Tenable Research will classify the reported Citrix NetScaler zero-day vulnerabilities as part of Vulnerability Watch once CVE IDs have been assigned.

Has Tenable released any product coverage for these vulnerabilities?

No. Once CVE IDs are assigned and patches are released, this post will be updated with plugin links. As always, customers can expect that forthcoming plugins will appear in the Plugins Pipeline as they are released.

r/Citrix thread: “Netscaler leak?”

watchTowr post on X: Citrix NetScaler RCE confirmation

Kevin Beaumont on Mastodon: Zero-day confirmation

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

The world’s leading AI-powered exposure management platform.

Thank you for your interest in Tenable One. A representative will be in touch soon.

Tenable One Cloud Exposure

Close cloud exposure with the actionable cloud security platform.

Thank you for your interest in Tenable One Cloud Exposure. A representative will be in touch soon.

Tenable Security Center

Identify and prioritize vulnerabilities based on risk to your business. Managed on premises.

Thank you for your interest in Tenable Security Center. A representative will be in touch soon.

Tenable Patch Management

Streamline security and IT collaboration and shorten the mean time to remediate with automation.

Thank you for your interest in Tenable Patch Management. A representative will be in touch soon.

Tenable Enclave Security

Identify, understand and close IT and container vulnerabilities.

Thank you for your interest in Tenable Enclave Security. A representative will be in touch soon.

Tenable One Attack Surface Management

Gain visibility into your internet-connected assets to eliminate blind spots and unknown sources of risk.

Thank you for your interest in Tenable One Attack Surface Management. A representative will be in touch soon.

Tenable One AI Exposure

See, secure, and manage how your teams use AI tools.

Thank you for your interest in Tenable One AI Exposure. A representative will be in touch soon.

Tenable One OT Exposure

Close OT exposure with the unified security solution for converged OT/IT environments.

Thank you for your interest in Tenable One OT Exposure. A representative will be in touch soon.

See Tenable in action

Want to see how Tenable can help your team find and fix critical cyber weaknesses that put your business at risk? Complete this form to get a custom quote or demo.

You should receive a confirmation email shortly and one of our representatives will be in touch.

Learn How Tenable Helps Achieve SLCGP Cybersecurity Plan Requirements

You should receive a confirmation email shortly and one of our Sales Development Representatives will be in touch. Route any questions to [email protected] .

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable One Vulnerability Management trial also includes Tenable One Web App Scanning.

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable One Vulnerability Management. A representative will be in touch soon.

Try Tenable One Web App Scanning

Your Tenable One Web App Scanning trial also includes Tenable One Vulnerability Management.

Buy Tenable One Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable Web App Scanning. A representative will be in touch soon.

Try Tenable Nessus Professional free

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Fill out the form below to continue with a Nessus Pro trial.

Buy Tenable Nessus Professional

Buy a multi-year license and save. Add Advanced Support for access to phone, community, and chat support 24 hours a day, 365 days a year.

Try Tenable Nessus Expert free

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional? Upgrade to Nessus Expert free for 7 days.

With Advanced Support for Nessus Pro, your teams will have access to phone, Community, and chat support 24 hours a day, 365 days a year. This advanced level of technical support helps to ensure faster response times and resolution to your questions and issues.

Advanced Support Plan Features

Phone support 24 hours a day, 365 days a year, available for up to ten (10) named support contacts.

Chat support available to named support contacts, accessible via the Tenable Community is available 24 hours a day, 365 days a year.

Tenable Community Support Portal

All named support contacts can open support cases within the Tenable Community. Users can also access the Knowledge Base, documentation, license information, technical support numbers, etc.; utilize live chat, ask questions to the Community, and learn tips and tricks from other Community members.

Initial Response Time

P1-Critical: < 2 hr P2-High: < 4 hr P3-Medium: < 12 hr P4-Informational: < 24 hr

Support contacts must be reasonably proficient in the use of information technology, the software they have purchased from Tenable, and familiar with the customer resources that are monitored by means of the software. Support contacts must speak English and conduct support requests in English. Support contacts must provide information reasonably requested by Tenable for the purpose of reproducing any Error or otherwise resolving a support request.

Extracted Entities

Attack Types (1)

Vulnerabilities (1)