Two unpatched Citrix NetScaler zero-days are exploited with no fix published
watchTowr has documented two remote-code-execution zero-days in Citrix NetScaler ADC and Gateway, already exploited before any fix existed. With nothing published by Citrix, the only defense is isolation: preserve evidence, cut the appliance off the network and keep management off the internet.
September 26, 2026. watchTowr announces on X that two zero-day remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited. September 26, 2026, 22:19 UTC. A follow-up post fills in the picture: two RCE flaws, both unpatched, exploited before any fix existed, discovered during forensic investigations. Week of September 28, 2026. The window in which Citrix is expected to communicate and ship patches — with nothing guaranteed. Why it matters: NetScaler sits at the network edge — VPN, remote access, load balancing, authentication — and an unpatched RCE in that position is a front door left open into the rest of the estate.
Two flaws, no fix, no bulletin
The situation is unusual, and that is exactly what makes it dangerous. watchTowr has published no technical evidence, named no victim, and said nothing about whose forensic investigations surfaced the exploitation. Citrix — or rather its owner, Cloud Software Group — had confirmed nothing at publication time: no bulletin, no patch, no indicators of compromise, not even a list of affected versions.
watchTowr’s first post on X, on September 26, 2026, said it was reacting to rumors of several unpatched NetScaler RCE flaws in the wild. “While details are scarce, the information is credible,” the firm wrote. The 22:19 UTC post gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before a fix existed, found during forensic investigations. Citrix was expected to communicate and ship fixes “early in the week of September 28.”
These new flaws are not the authentication bypass CVE-2026-19490, which Citrix fixed on August 19, 2026 and which CISA added to its KEV catalog on September 9, 2026. For that flaw, a fix has existed since August. For the two new ones, nothing exists yet — and that is the difference between a bulletin handled as an emergency and an incident handled in uncertainty.
What NetScaler exposes at the edge
NetScaler ADC and NetScaler Gateway are not ordinary appliances. They terminate SSL, balance load, and — crucially — carry remote access: SSL VPN, ICA Proxy, CVPN, RDP Proxy. They authenticate users before those users reach the internal network. An RCE in that position means an attacker does not need to bypass authentication — they execute code on the appliance itself, ahead of every control.
This is a script recent history has already run. CVE-2019-19781 (“Shitrix”) was mass-exploited in January 2020. CVE-2023-3519 followed in 2023. In 2025, a NetScaler flaw exploited as a zero-day against Dutch organizations led the Dutch NCSC to publish verification scripts. And in August 2026, watchTowr had already shown that a NetScaler heap overflow fixed in June could be turned into remote code execution — a sign of how intimately the firm knows this attack surface.
The scanning clock is already running. When Citrix shipped the August bulletin for CVE-2026-19490, Rapid7 reported no active exploitation at publication — a status that rarely survives more than a few days for an authentication flaw on an edge appliance, because NetScaler appliances rank among the most-scanned targets on the internet the moment a bulletin drops. With these two new flaws there is no bulletin to wait on, so the operator is the detection layer: watch the access logs, restrict exposure, and assume the internet-wide scanners are ahead of you. The absence of a CVE and an IoC list is not a comfort — it means your SIEM has nothing to match on.
The 2025 precedent: patching is not enough
In 2025, after the zero-day exploitation of a NetScaler flaw against Dutch targets, the Netherlands’ National Cyber Security Centre stressed that updating alone does not remove the risk. An attacker who gained access before the patch keeps it after the update. The agency therefore distributed verification scripts covering the live appliance, core dumps and full images, with an honest README: the script looks for indicative files, is tied to no specific vulnerability, and offers no guarantee of effectiveness.
That logic applies word for word here. Because the exploitation watchTowr describes happened before any fix existed, installing the future patch will never tell an operator whether an attacker is already inside. This is the difference between a “patch now” incident and a “rule out compromise” incident.
Online, isolated, or off?
With no bulletin, there is no official mitigation and no published indicator of compromise. Every NetScaler operator must therefore settle a three-way decision themselves: leave the appliance online, isolate it, or power it down.
Some administrators have already chosen the third option. On Reddit, a thread in r/Citrix reports that an administrator received a call from their IT supplier’s security team instructing them to shut their NetScalers down immediately, with no further detail. Others in the thread said their organizations had done the same. The source of those supplier warnings is unestablished, but the reflex says something about ground-level confidence: when the bulletin does not exist, cutting exposure is the only certain mitigation.
The version question adds further uncertainty. Citrix has not said whether the August builds — 14.1-73.32 and 13.1-63.21 — or newer builds are affected by the new flaws. And NetScaler 13.1 reached end of maintenance on September 15, 2026: nothing guarantees it will receive a fix.
Citrix’s own guidance for suspected compromise
Citrix has long published a procedure for appliances suspected of compromise. It serves as a minimal checklist while no bulletin exists. In order: preserve evidence first — a snapshot of a VPX instance, the logs on remote syslog servers and the NetScaler Console, a support bundle, and a core dump of the packet engine. Then isolate the appliance from the network. Change every service-account password and secret stored on it, reset the passwords of users who signed in through it, and revoke its certificates and private keys. Finally, keep the management interface off the internet — “the NetScaler Management Services should never be exposed to the public internet,” the guidance states.
That last line is the only genuinely preventive mitigation that exists today, with no bulletin. An appliance whose management interface is not exposed, and whose VPN access is restricted to known ranges, shrinks the surface an unknown RCE can operate on, even with no patch.
Verdict
If you run internet-exposed NetScaler ADC or Gateway, treat this as a potential compromise, not a late patch: preserve evidence, sweep your logs, and be ready to isolate — Citrix’s first communication can land at any moment and trigger mass scanning within hours. If you cannot drop remote access right now, restrict the VPN and the management interface to known address ranges and monitor the appliance as an already-suspect host, not a healthy one. If your appliances carry critical traffic, document the isolation and rebuild procedure today: a flaw exploited before a patch leaves, by definition, a doubt that only a clean rebuild clears. NetScaler has become the edge target once more — and this time, the first defense is not a patch, it is exposure reduction.