VMTech
Discuss a project →

Two Unpatched NetScaler RCE Zero-Days Reportedly Exploited

Two Unpatched NetScaler RCE Zero-Days Reportedly Exploited

Security firm watchTowr has warned that two unpatched zero-day vulnerabilities enabling remote code execution in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited. In posts published on September 26, the firm said both flaws were exploited before a fix existed and were identified during forensic investigations.

Citrix had not confirmed the vulnerabilities, named affected releases or issued a security bulletin as of Sunday morning. The company had also not published a workaround or indicators of compromise, leaving administrators without vendor guidance for determining exposure.

Separate from August authentication bypass

The reported flaws are distinct from CVE-2026-19490, an authentication bypass that Citrix fixed on August 19. CISA added that vulnerability to its Known Exploited Vulnerabilities catalog on September 9, but the existence of a patch for that issue does not address the newly reported RCE flaws.

Citrix has not said whether NetScaler ADC and Gateway builds 14.1-73.32 and 13.1-63.21, released in August, are affected, nor whether newer builds are vulnerable. The support position for NetScaler 13.1 is also uncertain: the release reached End of Maintenance on September 15, and Citrix has not stated whether it will receive a fix.

Edge exposure raises operational pressure

NetScaler ADC and NetScaler Gateway commonly sit at the enterprise edge, providing VPN and remote access, load balancing and user authentication. That role makes an unpatched remote-code-execution report operationally significant, because a successful intrusion can precede the availability of a corrective update.

watchTowr said details remained scarce in its first post, then stated in a later update that it expected Citrix communications and patches early in the week of September 28. The firm did not publish technical evidence, identify victims or say whose forensic investigations detected the activity. Separately, administrators on Reddit reported advice from suppliers to take appliances offline, but the origin of those warnings has not been established.

Preserve evidence before changing systems

Citrix's existing guidance for suspected NetScaler compromise recommends preserving evidence before taking remediation steps. This includes a VPX snapshot, logs retained by remote syslog servers and NetScaler Console, a technical support bundle, and a packet-engine core dump.

The vendor then advises isolating the appliance, changing every service-account password and stored secret, resetting passwords for users who authenticated through it, and revoking its certificates and private keys. Citrix also states that NetScaler Management Services should never be exposed to the public internet.

After a zero-day incident against Dutch organisations in 2025, the Netherlands' National Cyber Security Center cautioned that updating alone may not remove access gained before a patch. Its check scripts can inspect a live appliance, core dumps and full NetScaler images, although the live-appliance script says it searches for compromise-indicating files, is not tied to one vulnerability and offers no guarantee of effectiveness.

For businesses running NetScaler, the immediate decision is whether systems can remain online, be isolated or be powered down while facts and a vendor fix emerge. A patch, when available, should be paired with evidence preservation, credential and certificate rotation, and an assessment for pre-patch compromise.

#cybersecurity#netscaler#vulnerability#incidentresponse
Open analytics
On the site 4 views
min read 4 27.09.2026
Instagram

Two Unpatched NetScaler RCE Zero-Days Reportedly Exploited

Open the post on Instagram ↗