Warning: Two unpatched Citrix NetScaler RCE zero-days face active exploitation

Warning: Two unpatched Citrix NetScaler RCE zero-days face active exploitation

By Lukas Brandt
Publication Date: 2026-09-27 08:50:00

Security firm watchTowr says attackers are exploiting two unpatched remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix has not confirmed the vulnerabilities, issued a fix or published indicators of compromise, leaving administrators to choose between isolation and continued exposure.

Two unpatched vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are under active exploitation, security firm watchTowr said Sept. 26. The flaws allow remote code execution, and Citrix has not confirmed them or released a patch.

NetScaler appliances sit at the edge of enterprise networks. Organizations use them for VPN access, remote authentication, application delivery and load balancing. An attacker who gains code execution on one of these systems could reach sensitive traffic, credentials and connected services.

The report concerns two new flaws, not CVE-2026-19490, an authentication-bypass vulnerability that Citrix patched Aug. 19. The…