Citrix NetScaler Zero-Days Actively Exploited, Threatening Critical Infrastructure
Two unpatched zero-day remote code execution vulnerabilities in Citrix NetScaler are reportedly being actively exploited in the wild, prompting urgent warnings from security researchers.

Security professionals are on high alert following reports of two undisclosed zero-day remote code execution (RCE) vulnerabilities actively being exploited in Citrix NetScaler appliances. The intelligence, initially flagged by threat intelligence firm watchTowr, indicates that these flaws are unpatched and have been identified during forensic investigations. While Citrix has yet to release official confirmation, technical details, or specific CVE identifiers, the company is expected to provide communications and fixes early next week.
The scarcity of verified information presents a significant challenge for defenders, who must make critical security decisions based on limited, albeit credible, intelligence. watchTowr described the situation as a serious warning, emphasizing that while exploitation is believed to be occurring, the full scope and technical details remain unconfirmed by the vendor. This ambiguity forces organizations to consider drastic measures, such as taking internet-exposed NetScaler appliances offline, which could disrupt essential services like VPN access, application delivery, and authentication.
It is crucial to distinguish these emerging reports from previously disclosed vulnerabilities. The current alert is not to be confused with Citrix's August 19 bulletin concerning CVE-2026-19490 and CVE-2026-19489. CVE-2026-19490, an authentication bypass flaw, and CVE-2026-19489, a memory overflow issue, have already seen active exploitation and were addressed by Citrix with specific patches. The new reports specifically point to two distinct RCE vulnerabilities that are separate from these earlier disclosures.
For the August vulnerabilities, Citrix recommended upgrading NetScaler ADC and Gateway versions 14.1 to 14.1-73.32 or later, and 13.1 to 13.1-63.21 or later. Specific fixed baselines were also provided for specialized editions. However, no workarounds were offered for these particular flaws, and the guidance applied to customer-managed appliances, not cloud services.
In the absence of immediate vendor clarification on the new zero-days, organizations are strongly advised to take proactive steps. This includes conducting a thorough inventory of all NetScaler instances, verifying their exact builds and internet exposure, and strictly limiting management access. Implementing compensating controls before public interfaces is also recommended. Security teams should preserve logs and forensic images, meticulously review authentication events, new sessions, configuration changes, and any unusual process activity or network connections.
For organizations unable to tolerate the potential risk associated with these unpatched vulnerabilities, the most prudent course of action may be to isolate or completely shut down exposed appliances. This decision should be made within an approved business-continuity framework to minimize operational impact. Continuous monitoring of Citrix's official security bulletin channels for patches and deployment guidance is essential, rather than relying solely on fragmented social media reports.
This incident underscores the persistent challenges in securing internet-facing remote access infrastructure. It highlights the critical need for rapid asset discovery, robust emergency patching capabilities, centralized logging, and well-rehearsed incident-response procedures, especially when security teams must act decisively even before complete technical disclosures are available.