NEWS

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

watchTowr warns two unconfirmed Citrix NetScaler RCE zero-days are being exploited; Citrix has issued no CVE, patch, or advisory yet.

Dylan H.

News Desk

September 27, 2026
10 min read
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

watchTowr Warns of Two New Unpatched NetScaler RCE Zero-Days

On September 26, 2026, security firm watchTowr said it was "rapidly reacting" to credible reports of two new, unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that are being actively exploited in the wild. Neither flaw has been assigned a CVE identifier, and Citrix has not confirmed the vulnerabilities, published technical details, named affected builds, or released a fix as of this writing. watchTowr says both bugs were "discovered during forensic investigations" and that Citrix communications and patches are expected "early next week" — but because exploitation allegedly began before any fix existed, administrators cannot assume that installing a future patch alone will undo any access an attacker already gained. Critically, this warning is not about CVE-2026-19490, the critical NetScaler authentication-bypass flaw Citrix patched on August 19, 2026, and which CISA added to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026 — watchTowr and several administrators have explicitly pushed back on online chatter conflating the two.


Advisory at a Glance

AttributeValue
Disclosed bywatchTowr, September 26, 2026 (via X/social media, not a formal advisory)
Affected productsCitrix NetScaler ADC and NetScaler Gateway (customer-managed appliances)
Vulnerability countTwo, both described as unauthenticated remote code execution
CVE ID(s)None assigned as of publication
Vendor confirmationNone — Citrix has not published an advisory, technical details, affected builds, or indicators of compromise
Distinct fromCVE-2026-19490 (auth bypass, patched Aug 19, 2026) and CVE-2026-19489 (memory-overflow DoS), covered by Citrix bulletin CTX696939 / NCSC-2026-0318
Active exploitationReported by watchTowr; discovered "during forensic investigations"; no victims or specific campaigns named publicly
Patch timelineCitrix advisory and fixes reportedly expected "early in the week of September 28, 2026"
Regulatory backdropEU Cyber Resilience Act (in force since September 11, 2026) reportedly required Citrix to notify European authorities before its investigation and patch were complete
Interim guidanceNo official Citrix workaround published; community-suggested mitigations (IP allowlisting, disabling DTLS) are unverified

How This Unfolded

A Credible But Detail-Light Warning

watchTowr's first public post on Saturday, September 26, said the firm was "rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild," adding: "While details are scarce, the information is credible. watchTowr Platform clients have been made aware of their Citrix NetScaler exposure." A fuller follow-up statement later that evening gave the report more shape: two separate vulnerabilities, both RCE, both unpatched, exploited before any fix existed, discovered "during forensic investigations," with Citrix communications and fixes expected early the following week. watchTowr has not published proof-of-concept code, named a victim organization, or explained whose forensic investigation surfaced the exploitation. When a researcher publicly questioned the announcement — "If details are scarce how is the intel credible?" — watchTowr responded that it had verified the reports with authoritative sources.

A Weekend of Rumor, Reddit, and Regulatory Pressure

The warning spread quickly through a Reddit r/Citrix thread titled "Netscaler leak?" that drew more than 75 upvotes and 50 comments over the weekend, alongside amplification from independent social accounts. Multiple Managed Service Providers (MSPs), MDR vendors, and national cybersecurity agencies reportedly told their own clients to shut down NetScaler appliances rather than wait for a fix. The Dutch National Cyber Security Centre (NCSC-NL) reportedly issued informal notifications to some organizations through CERT teams and suppliers rather than a public advisory, and reports on how that notification reached administrators were inconsistent — one administrator said their organization received direct word describing the issue as "a big one" with "no fix yet," while another found no notice on the NCSC website and no email from the agency. Adding to the pressure, the EU Cyber Resilience Act, which took effect September 11, 2026, requires vendors to report actively exploited vulnerabilities to European authorities on a tight timeline — reportedly forcing Citrix to file a report before its own investigation and patch were complete.

What Makes This RCE — and How It Differs From August's Bug

The August vulnerabilities that many observers initially assumed this warning referred to are well understood: CVE-2026-19490 is an authentication-bypass flaw that lets an unauthenticated attacker reach protected resources when a NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), an AAA virtual server, or a SAML Identity Provider, while CVE-2026-19489 is a memory-overflow denial-of-service issue affecting devices configured as a SIP ALG within a Large Scale NAT (LSN) group. Both were addressed in Citrix's CTX696939 bulletin (tracked by NCSC-NL as NCSC-2026-0318) with fixed builds 14.1-73.32 and 13.1-63.21 (plus FIPS/NDcPP variants). watchTowr and administrators alike have stated plainly that the new zero-days are a different pair of bugs. Per secondary reporting that CosmicBytez Labs has not independently verified, at least one of the new flaws may involve injecting and executing shellcode directly in appliance memory rather than dropping a file to disk — a technique that would evade traditional file-based antivirus and EDR detection if accurate. Citrix has not said whether devices already running the August-patched builds remain exposed to the new bugs, and the uncertainty is compounded by the NetScaler 13.1 branch reportedly reaching End of Maintenance on September 15, 2026, raising open questions about whether that branch will receive a fix at all.

Why Patching Alone May Not Be Enough

Because watchTowr says exploitation of these zero-days predates any available fix, a future Citrix patch will not by itself tell an administrator whether an attacker already gained access. This mirrors a 2025 precedent: after a different NetScaler flaw was exploited as a zero-day against Dutch organizations, NCSC-NL warned that simply updating did not remove the risk, since an attacker could retain access obtained before the patch shipped, and it directed administrators to run dedicated check scripts instead of trusting the patch alone. NCSC-NL has gone further before — in January 2020, during attacks on CVE-2019-19781, the agency told organizations to consider switching off Citrix ADC and Gateway entirely after concluding that Citrix's interim mitigations at the time did not work reliably.


Impact Assessment

Impact AreaDescription
Edge exposureNetScaler ADC/Gateway sit at the network edge handling VPN, remote access, load balancing, and authentication — compromise can provide deep internal network access
OperationalSome administrators, MSPs, and MDR vendors have pre-emptively taken appliances offline, disrupting VPN and load-balanced services over the weekend
Forensic uncertaintyBecause exploitation reportedly predates any fix, a future patch cannot by itself confirm or rule out prior compromise
Information reliabilityThe absence of CVEs, technical detail, or vendor confirmation leaves defenders relying on secondhand and social-media reporting, raising the risk of both under- and over-reaction
RegulatoryThe EU Cyber Resilience Act's tightened vendor-disclosure timeline appears to have pressured Citrix to notify regulators before it was ready to disclose publicly — a dynamic likely to recur with future vendor incidents
Industry patternThis is the second major NetScaler exploitation event of the second half of 2026, following the August CVE-2026-19489/CVE-2026-19490 bulletin, and reinforces NetScaler appliances as a persistent high-value target for intrusion

Recommendations

For NetScaler Administrators

  • Inventory every NetScaler ADC/Gateway instance and record exact build numbers now, before official guidance narrows the list of affected versions.
  • Restrict management-plane (NSIP) access to trusted management networks only, and remove any incidental internet exposure of the management interface immediately, independent of this specific advisory.
  • Where risk tolerance is low, consider taking internet-facing appliances offline or restricting inbound access to an allowlist of known-good source IP ranges until Citrix publishes guidance — mirroring interim advice Mandiant has given during prior NetScaler exploitation campaigns.
  • Preserve forensic evidence before any remediation step: a VPX snapshot, logs already offloaded to a remote syslog server or NetScaler Console, a technical support bundle, and a core dump of the packet engine, per Citrix's standard compromise-response guidance.

For Security and Incident Response Teams

  • Treat any NetScaler appliance that has been internet-facing in recent months as potentially already compromised until proven otherwise — once a patch ships, installing it will not answer whether an attacker got in first.
  • Review authentication logs, administrative session logs, and outbound traffic from both management and data interfaces for anomalies predating this weekend's warning.
  • Monitor NCSC-NL, CISA, and Citrix's own security bulletin page directly rather than relying solely on social-media summaries, and be ready to move quickly once CVE IDs and affected-build lists are published.
  • Do not treat community-sourced mitigations (disabling DTLS, IP allowlisting) as validated fixes — apply them only as defense-in-depth measures, not as a substitute for vendor guidance.

For Leadership and Risk Owners

  • Weigh the operational cost of pre-emptive appliance isolation against the cost of a confirmed compromise; multiple MSPs, MDR vendors, and national agencies already recommended shutdown over the weekend of September 26-27.
  • Confirm incident-response and legal teams are engaged now, given the EU Cyber Resilience Act's tightened vendor-disclosure timelines and the possibility that retained logs will later need to support a breach-notification determination.
  • Ask your NetScaler vendor or reseller for a direct, verifiable confirmation channel rather than relying on Reddit threads or informal CERT forwards, given the inconsistent notification reports circulating this weekend.

Key Takeaways

  1. watchTowr says two new, unpatched Citrix NetScaler RCE zero-days are being actively exploited, disclosed via social media on September 26, 2026 — no CVE IDs, technical details, or vendor confirmation exist yet.
  2. The flaws are explicitly distinct from CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (denial of service), which Citrix already patched on August 19, 2026, and which CISA added to its KEV catalog on September 9.
  3. Citrix has not said which builds are affected, including whether appliances already updated to the August fixed versions (14.1-73.32 and 13.1-63.21) remain exposed; an advisory and patches are reportedly expected the week of September 28.
  4. Because watchTowr says exploitation predates any fix, patching alone will not confirm whether an attacker already gained access — echoing NCSC-NL guidance from a 2025 NetScaler zero-day that told administrators to run check scripts rather than trust a patch alone.
  5. Multiple MSPs, MDR vendors, and national cybersecurity agencies reportedly urged clients to shut down NetScaler appliances over the weekend, though notification has been inconsistent and some administrators report receiving no official word at all.
  6. With no vendor-confirmed technical detail available, administrators should inventory their NetScaler fleets, lock down management access, preserve forensic evidence, and monitor official Citrix, CISA, and NCSC-NL channels directly rather than relying on secondhand reporting.

Sources