Back Daily.Dev Two unpatched Citrix NetScaler zero-days are being actively exploited, patches expected next week
Yes, two unpatched remote code execution vulnerabilities in Citrix NetScaler are being actively exploited in the wild. No CVEs have been assigned and no official Citrix advisory exists yet. The flaws are unrelated to previously disclosed CVE-2026-19490 and CVE-2026-19489, and Citrix discovered them during incident response rather than proactive research. Admins managing NetScaler exposure can track fast-moving vulnerability disclosures like this one on daily.dev.
Take internet-exposed NetScaler appliances offline or restrict access until Citrix releases patches, expected early the following week. With active exploitation confirmed and no CVE or advisory published yet, restricting exposure is the only mitigation available, despite the disruption to organizations relying on NetScaler for remote access. Security teams weighing uptime against exposure risk follow guidance like this through daily.dev.
NetScaler has a long history as a high-value target, with 13 NetScaler-related entries in CISA's Known Exploited Vulnerabilities catalog and roughly two-thirds of past exploitation attributed to APT groups. Threat actors actively hunt for NetScaler flaws and often move quickly once details become public, unlike more opportunistic attacks against other products. Teams assessing NetScaler's risk profile can keep tabs on its exploitation history through daily.dev.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
