Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
thehackernews.com Sep 27, 2026

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

AI-summarised brief · reviewed before publication

Security firm watchTowr reported on September 26 that two previously unknown Citrix NetScaler ADC and NetScaler Gateway zero‑day flaws are being actively exploited to execute remote code. Citrix has not confirmed the vulnerabilities, issued a bulletin, or released patches, leaving administrators to decide whether to isolate or shut down the appliances. The flaws differ from the August‑19 authentication‑bypass CVE‑2026‑19490, which Citrix already fixed and CISA listed as a known exploited vulnerability. Details of the new bugs remain scarce; watchTowr said they were discovered during forensic investigations and that Citrix expects patches early in the week of September 28. Some organizations have already taken NetScaler devices offline based on supplier warnings, while others await official guidance. Enterprises with critical workloads consider risk unacceptable.

💡 Why It Matters

  • · The active exploitation of unpatched NetScaler gateways threatens the primary entry point for many corporate networks, forcing immediate operational decisions.