Skip to content
Warning: Two unpatched Citrix NetScaler RCE zero

Warning: Two unpatched Citrix NetScaler RCE zero

News.Lavx.Hu • September 27, 2026

Security firm watchTowr says attackers are exploiting two unpatched remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix has not confirmed the vulnerabilities, issued a fix or published indicators of compromise, leaving administrators to choose between isolation and continued exposure.

Two unpatched vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are under active exploitation, security firm watchTowr said Sept. 26. The flaws allow remote code execution, and Citrix has not confirmed them or released a patch.

NetScaler appliances sit at the edge of enterprise networks. Organizations use them for VPN access, remote authentication, application delivery and load balancing. An attacker who gains code execution on one of these systems could reach sensitive traffic, credentials and connected services.

The report concerns two new flaws, not CVE-2026-19490, an authentication-bypass vulnerability that Citrix patched Aug. 19. The Cybersecurity and Infrastructure Security Agency added that older flaw to its Known Exploited Vulnerabilities catalog on Sept. 9.

Citrix has not said whether the new vulnerabilities affect appliances running builds 14.1-73.32, 13.1-63.21 or later releases. NetScaler 13.1 reached its scheduled end of maintenance Sept. 15, which raises a separate question whether Citrix will issue a fix for that branch.

What watchTowr reported

WatchTowr first warned credible reports of unpatched NetScaler remote-code-execution flaws in a post on X on Sept. 26. A later update said forensic investigations uncovered two vulnerabilities that attackers had exploited before a patch existed.

The firm has not named a victim, published technical details or released indicators of compromise. It expects Citrix to communicate the flaws and release patches during the week of Sept. 28.

WatchTowr previously showed that attackers could turn a NetScaler heap overflow, which Citrix patched in June, into remote code execution. That research adds context to the new warning but does not confirm that the same bug class affects the current incident.

Reports on described some security providers telling customers to shut down NetScaler appliances. One administrator said a supplier called with that advice but gave no technical details. Other commenters said their organizations had taken similar steps. The source of those warnings remains unconfirmed.

Administrators face an exposure decision

Citrix has not published a workaround or a check for the two new flaws. Operators must assess the risk of keeping an appliance online while they wait for vendor guidance.

Teams that can remove NetScaler from service should prepare for that option. Teams that must keep the appliance online should restrict access, remove management exposure from the internet and increase monitoring around authentication, configuration changes and outbound connections.

A patch will not show whether an attacker entered before the patch arrived. Organizations should treat a vulnerable appliance as a possible breach when its exposure, logs or network activity support that conclusion.

Citrix's response guidance

Citrix's existing support guidance for suspected NetScaler compromise calls for evidence preservation before changes alter the system. Administrators should collect:

A snapshot of a virtual VPX appliance, when available.

Logs from remote syslog servers and NetScaler Console.

A technical support bundle.

A core dump from the packet engine.

After evidence collection, teams should isolate the appliance from the network. They should change service-account passwords and secrets stored on the device, reset passwords for users who signed in through it and revoke certificates and private keys tied to the appliance.

Administrators should keep the management interface off the public internet. Citrix's guidance says the NetScaler management service should not face the internet.

Teams should also review identity-provider logs, VPN sessions, administrator activity and connections from the appliance to internal systems. An attacker who used NetScaler as an entry point may leave evidence outside the appliance itself.

Check scripts have limits

The Netherlands' National Cyber Security Centre published NetScaler check scripts after a 2025 zero-day attack against Dutch organizations. The scripts examine a live appliance, core dumps and full NetScaler images.

The NCSC says the live-appliance script searches for files that may indicate compromise. It does not target one vulnerability, and the agency does not guarantee that it will find every intrusion. The code received its last update in September 2025.

Administrators can review the NCSC Netherlands guidance and test the scripts against preserved evidence. A clean result cannot clear an appliance that lacks complete logs or that an attacker altered before the examination.

What to watch for

Cloud Software Group, Citrix's parent company, has not published an advisory on the new flaws as of Sept. 27. A vendor bulletin should identify affected versions, provide fixes or mitigations, describe exploitation evidence and explain how administrators can test for compromise.

Security teams should track the Citrix support portal and CISA's vulnerability catalog for updates. They should also ask managed-service providers to identify the source of any shutdown advice before making operational decisions.

Until Citrix publishes technical guidance, organizations should document their NetScaler versions, internet exposure, backup access paths and emergency shutdown procedures. That inventory will shorten the response when Citrix names the affected builds or releases a patch.

Please log in or register to join the discussion

Extracted Entities