Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
Key Takeaways Two new, unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler appliances are reportedly being actively exploited in the wild. Cybersecurity firm watchTowr...
Key Takeaways
- Two new, unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler appliances are reportedly being actively exploited in the wild.
- Cybersecurity firm watchTowr identified these zero-day flaws during forensic investigations, signaling a critical threat to organizations using NetScaler.
- Citrix has not yet released official details, CVEs, or patches for these newly reported vulnerabilities, leaving defenders in a challenging position.
- Some organizations have resorted to temporarily shutting down internet-exposed NetScaler devices to mitigate immediate risk, despite service disruption.
Unpatched NetScaler RCE Zero-Days Under Active Exploitation
Administrators of Citrix NetScaler are currently grappling with credible reports of two previously undisclosed remote code execution (RCE) vulnerabilities. These critical zero-day flaws are allegedly being actively leveraged in real-world attacks, presenting a significant and immediate threat to affected organizations.
Table Of Content
The cybersecurity firm watchTowr initially brought these issues to light, stating that the vulnerabilities were discovered during ongoing forensic investigations. While Citrix has yet to publish official technical details, CVE identifiers, affected product versions, or an advisory, watchTowr anticipates that the vendor will release communications and fixes in the near future.
The Emergence of New Threats
The alarm was first raised by widespread rumors concerning multiple unpatched NetScaler RCE vulnerabilities circulating in the wild. watchTowr quickly assessed this intelligence as credible, later confirming that two distinct vulnerabilities could enable remote code execution. The firm has, however, refrained from publicly disclosing specific exploitation paths, prerequisites, payloads, or forensic artifacts, citing the sensitivity of the ongoing situation and the lack of a vendor-confirmed disclosure.
A tweet from watchTowr on September 26, 2026, highlighted the urgency: “pic.twitter.com/Wufu7eMOcm“. This prompted immediate action from some organizations, which reportedly responded by taking internet-exposed NetScaler appliances offline. Such drastic measures, while effective in preventing immediate exploitation, can severely disrupt critical services like VPN access, application delivery, and authentication, underscoring the severity of the perceived threat given the privileged position of edge appliances at the network boundary.
For sensitive environments where patching or reliable mitigation for a potentially exploitable RCE flaw is not immediately available, temporarily removing exposed systems from service is often considered the most prudent decision.
Distinguishing from Prior Vulnerabilities
It is crucial not to confuse these newly reported RCE zero-days with the vulnerabilities disclosed in Citrix’s August 19 bulletin. That advisory addressed CVE-2026-19490 and CVE-2026-19489. CVE-2026-19490 is a critical authentication-bypass flaw, rated 9.3 on CVSS v4.0, impacting specific customer-managed NetScaler Gateway and AAA virtual-server configurations. CVE-2026-19489, with an 8.8 CVSS score, is a memory-overflow issue that requires SIP ALG on a Large Scale NAT group and can lead to unpredictable behavior or denial of service.
Active exploitation of CVE-2026-19490 has been well-documented. Singapore’s Cyber Security Agency issued a warning on September 7 regarding observed exploitation attempts, and CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9. Canada’s Cyber Center also urged emergency patching and continuous monitoring for unauthorized access. The watchTowr alert explicitly clarified that the latest concerns pertain to two distinct, unpatched RCE flaws, not the previously known authentication bypass.
For the August vulnerabilities, Citrix recommends upgrading NetScaler ADC and Gateway 14.1 to version 14.1-73.32 or later, and 13.1 to 13.1-63.21 or later. Specialized editions require fixed baselines of 14.1-73.32 FIPS and 13.1-37.277 for FIPS or NDcPP. Citrix has not provided workarounds for these earlier flaws, and the bulletin applies exclusively to customer-managed appliances, not Citrix-managed cloud services.
What You Should Do
- Inventory and Assess: Immediately identify and inventory all NetScaler instances within your environment, verifying exact builds and their exposure to the internet.
- Restrict Access: Implement stringent access controls for NetScaler management interfaces and place compensating security controls in front of all public-facing interfaces.
- Monitor Citrix Advisories: Regularly check Citrix’s official security bulletin channel for updates, patches, and deployment guidance, rather than relying solely on unofficial reports.
- Prepare for Incident Response: Preserve logs and forensic images from all NetScaler appliances. Conduct thorough reviews of authentication events, new sessions, configuration changes, unexpected processes, suspicious files, and anomalous outbound connections.
- Avoid Premature Wiping: Do not wipe or reimage potentially compromised devices until all necessary forensic evidence has been collected.
- Isolate or Shut Down: If your organization cannot accept the residual risk posed by these unpatched vulnerabilities, isolate or temporarily shut down exposed appliances following an approved business continuity plan.
- Review and Practice: This incident highlights the critical need for rapid asset discovery, robust emergency patching procedures, centralized logging, and regularly rehearsed incident response protocols, especially for internet-facing infrastructure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.