Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
September 27, 2026
Local AI Model Modifies Credential Dumper to Bypass EDR Detection
September 26, 2026
F-Droid 2.0 Released: Major Redesign Improves Open-Source Android App Discovery
September 26, 2026
Home/CyberSecurity News/Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
CyberSecurity News

Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Key Takeaways Two new, unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler appliances are reportedly being actively exploited in the wild. Cybersecurity firm watchTowr...

Sarah simpson
Sarah simpson
September 27, 2026 3 Min Read
3 0

Key Takeaways

  • Two new, unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler appliances are reportedly being actively exploited in the wild.
  • Cybersecurity firm watchTowr identified these zero-day flaws during forensic investigations, signaling a critical threat to organizations using NetScaler.
  • Citrix has not yet released official details, CVEs, or patches for these newly reported vulnerabilities, leaving defenders in a challenging position.
  • Some organizations have resorted to temporarily shutting down internet-exposed NetScaler devices to mitigate immediate risk, despite service disruption.

Unpatched NetScaler RCE Zero-Days Under Active Exploitation

Administrators of Citrix NetScaler are currently grappling with credible reports of two previously undisclosed remote code execution (RCE) vulnerabilities. These critical zero-day flaws are allegedly being actively leveraged in real-world attacks, presenting a significant and immediate threat to affected organizations.

Table Of Content

  • Key Takeaways
  • Unpatched NetScaler RCE Zero-Days Under Active Exploitation
  • The Emergence of New Threats
  • Distinguishing from Prior Vulnerabilities
  • What You Should Do

The cybersecurity firm watchTowr initially brought these issues to light, stating that the vulnerabilities were discovered during ongoing forensic investigations. While Citrix has yet to publish official technical details, CVE identifiers, affected product versions, or an advisory, watchTowr anticipates that the vendor will release communications and fixes in the near future.

The Emergence of New Threats

The alarm was first raised by widespread rumors concerning multiple unpatched NetScaler RCE vulnerabilities circulating in the wild. watchTowr quickly assessed this intelligence as credible, later confirming that two distinct vulnerabilities could enable remote code execution. The firm has, however, refrained from publicly disclosing specific exploitation paths, prerequisites, payloads, or forensic artifacts, citing the sensitivity of the ongoing situation and the lack of a vendor-confirmed disclosure.

A tweet from watchTowr on September 26, 2026, highlighted the urgency: “pic.twitter.com/Wufu7eMOcm“. This prompted immediate action from some organizations, which reportedly responded by taking internet-exposed NetScaler appliances offline. Such drastic measures, while effective in preventing immediate exploitation, can severely disrupt critical services like VPN access, application delivery, and authentication, underscoring the severity of the perceived threat given the privileged position of edge appliances at the network boundary.

For sensitive environments where patching or reliable mitigation for a potentially exploitable RCE flaw is not immediately available, temporarily removing exposed systems from service is often considered the most prudent decision.

Distinguishing from Prior Vulnerabilities

It is crucial not to confuse these newly reported RCE zero-days with the vulnerabilities disclosed in Citrix’s August 19 bulletin. That advisory addressed CVE-2026-19490 and CVE-2026-19489. CVE-2026-19490 is a critical authentication-bypass flaw, rated 9.3 on CVSS v4.0, impacting specific customer-managed NetScaler Gateway and AAA virtual-server configurations. CVE-2026-19489, with an 8.8 CVSS score, is a memory-overflow issue that requires SIP ALG on a Large Scale NAT group and can lead to unpredictable behavior or denial of service.

Active exploitation of CVE-2026-19490 has been well-documented. Singapore’s Cyber Security Agency issued a warning on September 7 regarding observed exploitation attempts, and CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9. Canada’s Cyber Center also urged emergency patching and continuous monitoring for unauthorized access. The watchTowr alert explicitly clarified that the latest concerns pertain to two distinct, unpatched RCE flaws, not the previously known authentication bypass.

For the August vulnerabilities, Citrix recommends upgrading NetScaler ADC and Gateway 14.1 to version 14.1-73.32 or later, and 13.1 to 13.1-63.21 or later. Specialized editions require fixed baselines of 14.1-73.32 FIPS and 13.1-37.277 for FIPS or NDcPP. Citrix has not provided workarounds for these earlier flaws, and the bulletin applies exclusively to customer-managed appliances, not Citrix-managed cloud services.

What You Should Do

  • Inventory and Assess: Immediately identify and inventory all NetScaler instances within your environment, verifying exact builds and their exposure to the internet.
  • Restrict Access: Implement stringent access controls for NetScaler management interfaces and place compensating security controls in front of all public-facing interfaces.
  • Monitor Citrix Advisories: Regularly check Citrix’s official security bulletin channel for updates, patches, and deployment guidance, rather than relying solely on unofficial reports.
  • Prepare for Incident Response: Preserve logs and forensic images from all NetScaler appliances. Conduct thorough reviews of authentication events, new sessions, configuration changes, unexpected processes, suspicious files, and anomalous outbound connections.
  • Avoid Premature Wiping: Do not wipe or reimage potentially compromised devices until all necessary forensic evidence has been collected.
  • Isolate or Shut Down: If your organization cannot accept the residual risk posed by these unpatched vulnerabilities, isolate or temporarily shut down exposed appliances following an approved business continuity plan.
  • Review and Practice: This incident highlights the critical need for rapid asset discovery, robust emergency patching procedures, centralized logging, and regularly rehearsed incident response protocols, especially for internet-facing infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Local AI Model Modifies Credential Dumper to Bypass EDR Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us