Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Exploited in Attacks
Cybersecurity agencies and security providers are privately warning organizations about two unpatched remote code execution vulnerabilities in Citrix NetScaler. Citrix is reportedly preparing patches for release early next week.
Two unpatched zero-day vulnerabilities in Citrix NetScaler are reportedly being exploited in attacks, prompting cybersecurity agencies, security researchers, and IT providers to privately warn organizations ahead of next week’s expected patch release.
The first signs of the incident emerged when Citrix administrators reported on Reddit that their IT suppliers and security teams were privately contacting organizations and advising them to shut down their NetScaler appliances.
“We received a call from our IT supplier’s security team who advised us, without providing further details, to shut down Netscaler immediately.” an administrator wrote.
Other administrators said law enforcement agencies, CERTs, and national cybersecurity agencies had also contacted their organizations about the issue.
Cybersecurity firm watchTowr later issued a public warning that it was “quickly responding to rumors” that multiple unpatched remote code execution vulnerabilities in Citrix NetScaler were being exploited. The company said it had reviewed the information with “reputable sources.”
“We are currently responding quickly to rumors of multiple unpatched Citrix NetScaler RCE vulnerabilities in circulation. Details are lacking, but the information is reliable.” watchTowr said.
watchTowr said the warning is not related to CVE-2026-19490 or CVE-2026-19489, two NetScaler vulnerabilities that Citrix disclosed in August.
Reported NetScaler zero-days are separate from CVE-2026-19490
CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler appliances configured as AAA virtual servers or gateways in certain configurations.
As BleepingComputer reported earlier this month, researchers began observing attempts to exploit CVE-2026-19490 after a proof-of-concept exploit was published.
CISA subsequently added CVE-2026-19490 to its known and exploited vulnerability catalog on September 9.
watchTowr has since shared further information, stating that the current incident involves two unpatched remote code execution vulnerabilities that have already been exploited in the wild.
“Citrix communications and patches will be available early next week.” watchTowr said.
“Two vulnerabilities – both RCE. Unpatched, 0 days. Exploited in the field – discovered during forensics.”
BleepingComputer contacted Citrix about the reported zero-days but did not receive a response.
NCSC alert provides additional details
The Netherlands National Cyber Security Center (NCSC-NL) subsequently shared additional details in a pre-notification advisory report sent to organizations in the Netherlands.
Multiple people have shared copies of the notice online. It states that authorities received information from a European partner CERT about two critical zero-day vulnerabilities in Citrix NetScaler.
According to the notice, each vulnerability could allow independent remote code execution, and some could allow an attacker to place shellcode directly into memory. Technical details about the second vulnerability are still being researched.
The notice does not include CVE identifiers and states that Citrix has not published an advisory but is working on a patch expected early next week.
It also states that there was no indication of a breach at the time and that the NCSC was in contact with Citrix to obtain additional technical information and possible indicators of compromise.
According to the notification, Citrix discovered the vulnerability during an incident response investigation in a customer environment.
Those investigations identified active abuse, and Citrix subsequently filed a notification under the European Union’s Cyber Resilience Law.
The NCSC notice says the exploit has been confirmed by multiple Citrix customers around the world, but the NCSC says it is unclear whether the vulnerability has been exploited.
It also warned that exploitation attempts may increase after Citrix releases a patch or additional technical details about the vulnerabilities.
What NetScaler administrators should do now
Because updates to NetScaler appliances can cause downtime, the advance notice is intended to give organizations time to prepare, implement safeguards where possible, and install patches as soon as Citrix releases them, the NCSC said.
BleepingComputer contacted the Dutch NCSC to confirm whether the advisories circulating online are legitimate.
The agency declined to confirm the notice, but its response reflects reports from Citrix administrators that the cybersecurity agency privately shared information about the vulnerability.
“As part of its role as national CSIRT and sectoral CSIRT of designated organizations, NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7,” NCSC-NL told BleepingComputer.
“We are providing information and advice to organizations so that they can take appropriate action. As you are not part of our constituency, we are unable to release any further information at this time.”
Citrix has not formally disclosed the two vulnerabilities, and there are no publicly available CVE identifiers, affected version information, indicators of compromise, or official mitigation guidance for the reported zero-days.
Until Citrix releases a patch or official guidance, administrators should take Internet-exposed NetScaler appliances offline or restrict access to trusted networks and IP addresses whenever possible to reduce risk.
- Do not expose the NetScaler management interface to the Internet.
- Limit access to trusted IP addresses and networks.
- Prepare for potential downtime when applying the Citrix security update.
- Install the official Citrix patch as soon as it becomes available.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



