Skip to main content
← Back to blog

Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation

Security firm watchTowr says two new remote-code-execution zero-days in Citrix NetScaler ADC and Gateway are being exploited in the wild, with no vendor advisory or patch yet available. Some administrators are taking edge appliances offline; a fix is reportedly expected early next week.

#citrix#netscaler#zeroday#rce#vpn#networksecurity#kev
Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation

Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation

What happened

Security research firm watchTowr disclosed on September 26 that it has credible information pointing to two new, unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that are already being exploited in the wild. Unlike a typical disclosure, this warning did not come with a vendor advisory, a CVE identifier, or any published proof-of-concept — watchTowr says the flaws were identified during forensic investigations into real intrusions, and that Citrix communications and a fix are expected early in the week of September 28. Citrix has not confirmed the vulnerabilities as of this writing. In the absence of an official bulletin, reports have circulated on system administrator forums of organizations being advised by their security suppliers to take NetScaler appliances offline immediately as a precaution, without further technical detail being shared publicly.

Who is affected

NetScaler ADC and NetScaler Gateway are edge appliances used by a large number of enterprises to terminate VPN connections, manage remote access, perform load balancing, and handle authentication at the network perimeter — making them a high-value target by design. Because no advisory has been published, it is not yet clear which firmware versions or builds are affected, or whether the issue impacts the same August 2026 builds (14.1-73.32 and 13.1-63.21) that received a fix for a separate, previously disclosed NetScaler authentication bypass. It is worth noting that NetScaler 13.1 reached End of Maintenance on September 15, 2026, raising an open question about whether that branch will receive a fix at all.

Why it matters

This case is notable less for the technical mechanism, which remains undisclosed, and more for the situation it creates for defenders: two RCE-class vulnerabilities in a widely deployed perimeter product are reportedly being exploited before any patch, workaround, or indicator of compromise exists. Perimeter and VPN appliances are consistently among the most attractive initial-access targets because compromising one can expose the entire internal network behind it. Critically, watchTowr's account indicates exploitation began before any fix existed, meaning that once a patch does ship, simply applying it will not tell an administrator whether an attacker already gained access beforehand — a distinction that matters enormously for incident response planning. This is not the first time NetScaler zero-days have been exploited this way; a similar pattern played out in 2025 against Dutch organizations, prompting national authorities to warn that patching alone does not remove an attacker's foothold.

Technical details

  • Nature of the flaws: Two distinct, unpatched remote code execution vulnerabilities affecting NetScaler ADC and NetScaler Gateway, according to watchTowr.
  • Distinct from CVE-2026-19490: These are not the NetScaler authentication bypass Citrix patched on August 19, 2026, which CISA added to its KEV catalog on September 9, 2026.
  • Disclosure source: watchTowr states the vulnerabilities were found during forensic investigations, not through routine vendor coordination; no victim organizations, indicators of compromise, or technical exploitation details have been published as of this writing.
  • Vendor status: Citrix has not published an advisory, confirmed the flaws, or released a patch; a fix and communications are reportedly expected the week of September 28, 2026.
  • Affected builds: Unknown/unconfirmed; whether current supported builds (or the End-of-Maintenance 13.1 branch) are affected has not been stated by Citrix.

Recommended actions

  • Treat internet-facing NetScaler ADC/Gateway appliances as high risk right now: review exposure, and consider isolating management interfaces from the internet if this has not already been done — Citrix's own guidance states management interfaces should never be internet-facing.
  • Where feasible and risk tolerance allows, evaluate taking non-essential NetScaler appliances offline or restricting access to trusted source IPs until Citrix publishes an advisory and fix.
  • Preserve forensic evidence proactively: capture a snapshot/backup of the appliance configuration, retain remote syslog and NetScaler Console logs, and generate a technical support bundle, in case a compromise needs to be investigated retroactively.
  • Once Citrix publishes a fix, apply it immediately, but do not assume patching alone remediates a prior compromise — rotate all credentials and secrets stored on or accessible from the appliance, and revoke and reissue certificates and private keys.
  • Consider running publicly available NetScaler compromise-check scripts (such as those published by the Dutch NCSC for a prior incident) as a general hygiene check, understanding they are not guaranteed to detect this specific activity.
  • Monitor Citrix's security bulletins and CISA's KEV catalog closely for updates, and be prepared to act quickly once technical details are released, given the apparent gap between exploitation and disclosure in this case.

Sources

  • https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html