By The Stack
Publication Date: 2026-09-27 12:15:00
NetScaler users are scrambling to assess their risk and exposure amid as-yet-unconfirmed reports that a new pair of RCE zero days are being exploited.
Citrix NetScaler appliances are widely used by major banks, governments and other organisations as a gateway (VPN virtual server, ICA proxy, CVPN, or RDP proxy), a AAA virtual server, or depending on configuraiton, other critical network uses.
Attack surface management firm watchTowr warned that it believed “multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild” – saying it had “high confidence” in this and had “verified it with authoritative sources.”
The Dutch NCSC is rumoured to have been contacting those with exposed instances under TLP: Amber restrictions. It has yet to publish a public advisory with details.
A since-deleted version of the alleged NCSC advisory posted online, suggested that “The zero-day vulnerabilities were discovered during an investigation by Citrix at…

